Year2025 |
MonthAugust |
Reference number20250804 |
Impact areaVessel |
Incident locationTehran |
Incident countryIran |
Victim countryIran |
Victim identityFanava Group and 39 tankers and 25 cargo ships belonging to the National Iranian Tanker Company (NITC) and Islamic Republic of Iran Shipping Lines (IRISL) |
Victim TypeVessel |
MethodHacking |
Attacker countryUnknown |
In August 22, 2025, the hacktivist group Lab-Dookhtegan (also known as "Sewn Lips") executed one of the most consequential cyberattacks on Iran’s maritime infrastructure. After a similar attack in March and through compromising Fanava Group, the IT provider for state-controlled maritime giants NITC and IRISL, the group gained root-level access to Linux systems on board approximately 39 tankers and 25 cargo ships and disabled the critical Falcon satellite communication software. This plunged affected ships into total communication blackout, severing AIS tracking and ship-to-shore links. Additionally, the attackers carried out destructive overwrites of six storage partitions, wiping navigation logs, system configurations, recovery files, and even IP phone systems, escalating the disruption to require manual reinstallation of communications gear aboard each vessel. Forensic evidence shows that the hackers held access as early as May and June before launching the August attack which demonstrates prolonged infiltration and proving how a single supplier breach can lead to widespread operational collapse.