Suspected Cyber Incident Diverts LNG Carrier After Cargo-Control Failure

The Liberia-flagged Vivit Africa LNG failed to discharge a US LNG cargo in Italy after its crew lost access to internal control systems. A cyberattack is suspected, but investigators have not established the cause.

1690388577937
Walter (宏利)
Published 10:47

A Korean-owned LNG carrier has abandoned a planned discharge in Italy and diverted towards Spain after a systems failure that its crew believes may have been caused by a cyberattack.

The 174,000-cbm Vivit Africa LNG had loaded at the Cameron LNG export terminal in Louisiana and crossed the Atlantic before encountering technical problems as it approached Italy in early September. The vessel subsequently remained off the Italian coast without discharging at the Adriatic LNG terminal near Rovigo and then headed west towards Algeciras.

The vessel is owned by South Korea’s H-Line Shipping and operates under a long-term time charter to commodities trader Vitol, which confirmed its chartering involvement but declined to discuss the incident. The 2023-built ship is registered in Liberia and was constructed by Hyundai Samho Heavy Industries. 

Despite reports that hackers seized control of the ship’s safety systems, no independent technical investigation has yet confirmed that a malicious intrusion occurred.

Crew allegations go beyond confirmed findings

Crew members alleged that attackers temporarily interfered with steam-pressure and safety-valve systems while the vessel was passing through the Strait of Gibraltar. They later claimed that tank-pressure controls, pressure-relief valves and the boil-off gas management cycle were compromised as the vessel sailed in the Adriatic. 

Those are serious allegations on an LNG carrier, where maintaining cargo-tank pressure and managing boil-off gas are integral to safe operation. However, Splash said it had not independently verified the crew’s account.

The Italian Coast Guard offered a narrower description. It said the master reported a malfunction in systems used to monitor cargo parameters, requiring intervention by company technicians. The cause could not be determined, and the Chioggia Coast Guard issued an urgent navigational warning asking other vessels to keep clear while assisting on safety grounds. 

The incident was reported to Korean Register, and an investigation is continuing. H-Line Shipping and Korean Register had not commented publicly when the initial reports appeared.

The vessel carries equipment supplied by Kongsberg Maritime, whose portfolio includes navigation, positioning and propulsion technologies. The Norwegian supplier said it was aware of the reports but considered it too early to determine the cause or whether the event had security implications

Operational failure becomes a commercial problem

Whatever the eventual technical finding, the malfunction had already moved beyond the machinery space or control room: it interrupted a laden voyage and prevented the cargo from reaching its intended terminal.

That raises commercial questions separate from cyber attribution. The owner, technical manager, charterer, cargo interests and terminal may need to determine whether the vessel remained technically capable of performing the voyage, when it was safe to berth and discharge, and who bears the cost of delay, deviation and technical intervention.

The answers will depend on the charterparty, the cause of the failure and whether the incident triggers off-hire, force majeure, insurance or contractual notification provisions. Responsibility could also turn on whether the weakness originated in shipboard equipment, software configuration, remote access, shore-side connectivity or operational procedures.

Digital evidence will consequently be as important as physical inspection. System logs, access records, software changes and communications with shore-based technicians will be required to distinguish malicious interference from equipment failure or human error.

Cyber rules are moving closer to ship systems

The International Maritime Organization requires cyber risk to be addressed within shipping companies’ safety management systems. IMO Resolution MSC.428(98) called for administrations to ensure that cyber risks were incorporated no later than the first annual verification of a company’s Document of Compliance after January 1, 2021.

More detailed technical requirements have since entered the newbuilding process. The International Association of Classification Societies developed Unified Requirements E26 and E27, covering cyber resilience at ship level and for onboard systems and equipment. The requirements apply to relevant new ships contracted for construction from July 1, 2024.

As Vivit Africa LNG was delivered in 2023, the date distinction matters: the incident should not be used to imply non-compliance with rules introduced for later construction contracts.

Relevance for China’s expanding LNG fleet

For global shipowners, yards and equipment suppliers, the case provides a practical reference point as China’s LNG carrier fleet and domestic construction programme expand.

Cyber resilience will increasingly have to extend beyond bridge navigation and office IT to cargo monitoring, automation, propulsion, machinery management and vendor-maintenance connections. Clear separation between information-technology and operational-technology networks will matter, but so will the ability to maintain safe manual or local control when digital access becomes unreliable.

The investigation into Vivit Africa LNG may ultimately identify a conventional technical fault rather than a cyberattack. Even that outcome would not reduce the significance of the voyage disruption. The case demonstrates how an unexplained control-system failure can stop an LNG delivery, draw in coastal authorities and class, and expose uncertainty across the owner-charterer-terminal responsibility chain before its cause is known.

PURCHASE MEMBERSHIP

You need to purchase a membership to read this article

Payment