Year2025 |
MonthMarch |
Reference number20250303 |
Impact areaVessel |
Incident locationIran |
Incident countryIran |
Victim countryIran |
Victim identity50 ships belonging to the National Iranian Tanker Company (NITC) and 66 ships belonging to the Islamic Republic of Iran Shipping Lines (IRISL) |
Victim TypeVessel |
MethodHacking |
Attacker countryUnknown |
The cybersecurity company Cydome reported that the anti-Iranian government hacktivist group "Lab Dookhtegan" claimed to have disrupted communications on over 100 oil tankers associated with Iranian government-linked companies. The group announced via their Telegram channel that they successfully interrupted both internal and external communications of these vessels, effectively isolating them at sea. While Lab Dookhtegan did not disclose the specific methods used, it is believed they exploited vulnerabilities in the ships' satellite communication systems, such as VSAT terminals. These systems are known to be susceptible to cyberattacks, especially when default passwords remain unchanged. From those systems they can take complete control over all communications of the vessel and even spread out to the IT and OT systems.