Lab Dookhtegan Second Attack Against Iranian Ships

Year

2025

Month

August

Reference number

20250804

Impact area

Vessel

Incident location

Tehran

Incident country

Iran

Victim country

Iran

Victim identity

Fanava Group and 39 tankers and 25 cargo ships belonging to the National Iranian Tanker Company (NITC) and Islamic Republic of Iran Shipping Lines (IRISL)

Victim Type

Vessel

Method

Hacking

Attacker country

Unknown

Summary:

In August 22, 2025, the hacktivist group Lab-Dookhtegan (also known as "Sewn Lips") executed one of the most consequential cyberattacks on Iran’s maritime infrastructure. After a similar attack in March and through compromising Fanava Group, the IT provider for state-controlled maritime giants NITC and IRISL, the group gained root-level access to Linux systems on board approximately 39 tankers and 25 cargo ships and disabled the critical Falcon satellite communication software. This plunged affected ships into total communication blackout, severing AIS tracking and ship-to-shore links. Additionally, the attackers carried out destructive overwrites of six storage partitions, wiping navigation logs, system configurations, recovery files, and even IP phone systems, escalating the disruption to require manual reinstallation of communications gear aboard each vessel. Forensic evidence shows that the hackers held access as early as May and June before launching the August attack which demonstrates prolonged infiltration and proving how a single supplier breach can lead to widespread operational collapse.

Reference URL

https://blog.narimangharib.com/posts/2025%2F08%2F1755854831605?lang=en
https://www.darkreading.com/cyber-risk/hackers-knocked-out-iran-ship-comms
https://www.tradewindsnews.com/tankers/hackers-disable-communications-on-more-than-60-iranian-tankers-and-cargo-ships/2-1-1861711
https://maritimecybersecurity.nl/incident/yv060vvzgn