The LNG carrier Vivit Africa is still looking for solutions, a month after loading
An LNG carrier loaded with American gas is still looking for solutions off Barcelona, her cargo still aboard, a month after leaving Louisiana. Her crew reported losing access to shipboard systems in early September. She is the third ship in a month whose crew suspects a cyberattack. The Italian Coast Guard describes a malfunction whose cause could not be determined. Three successive publications, each more precise than the last, speak of a cyberattack, and none of them comes from a party with access to the ship.
This article is also available in French.
The third case in a month
In late August the US Coast Guard and the FBI boarded two energy carriers in the Gulf of Mexico, after indications that their networks had been compromised, and I covered that investigation in the article on those two ships. All three vessels have the United States at one end of their voyage. The first two were heading there, the oil tanker VL Prosperity loaded with crude in Egypt for Galveston, the gas carrier Kohaku expected in Texas, where she loaded liquefied petroleum gas in late August. The third was coming back from there, with liquefied natural gas loaded in Louisiana.
All three transited the Strait of Gibraltar, and all three accounts place the compromise there. The comparison stops at that point. No published source connects this carrier to the other two by an actor or by an entry point, the American agencies have announced no indication of compromise aboard her, and nothing puts her among the vessels they say they are tracking. Bloomberg nonetheless places the case after the two tankers, and beside the twenty or so merchant ships watched worldwide.
The first trace is a gas market notice
For this third ship, the first public trace is dated 7 September. At 14:13 UTC the operator of the Adriatic LNG terminal published an urgent message on the European gas market transparency platform [1]. It declared an unplanned reduction of its sendout into the grid, because a technical issue aboard an LNG carrier was preventing unloading. The ship is not named and no cause is given. The word cyber does not appear. This transparency obligation is addressed to gas buyers. It carries the date of 7 September, and no publication on the case is earlier than it.
A failure of the cargo monitoring systems
That technical issue was described eleven days later by the Italian Coast Guard, in a written answer to Bloomberg [2]. Captain Roberto D’Arrigo says the master reported a malfunction in the systems used to monitor cargo parameters, which required the company’s technicians to intervene. The cause could not be identified. The Chioggia Coast Guard intervened solely for navigation safety, issuing an urgent notice to mariners to keep their distance.
The same report gives what the crew went through. As the vessel sailed east through the Mediterranean and into the Adriatic, the seafarers found they could no longer reach some of the internal control systems. They reported the event early in the week of 7 September to Korean Register, the classification society that advises the ship on technical and safety matters, and presented it as a possible cyberattack. The vessel stayed off the Italian coast without discharging, then on 16 September gave up her call at the Rovigo terminal and headed west, towards Algeciras.
The account published in Moscow
A Russian publication had beaten that description by nine days. On 9 September at 17:13 UTC the energy trade outlet Neftegaz.RU named the ship and attributed her stoppage to a cyberattack said to have disabled all of her control and communication systems [3]. Its source is an unidentified informant in maritime logistics. No authority had spoken yet. This is the first publication to put the word cyberattack on the event, the crew having used it a few days earlier with their classification society, away from the public.
The relay through press releases
The same article appeared on 12 September on an American press release distribution platform, then on 14 September on another one [4] [5]. The two texts are identical. The header of the first has it issued from McKinney, a town in Texas, the second from Florence. The headline announces a cyberattack holding European gas reserves hostage on the eve of winter, and calls the United States an unreliable supplier. The argument fills the second half of the text, with figures on the American share of European LNG imports.
The loading at Cameron LNG in Louisiana is said to have been interrupted by the thermal fuse of the passive fire protection and the emergency shutdown. The cargo control system is said to have logged a series of alarms on the same day. The attackers would therefore have been watching operations from the loading port, on that text’s reading. Republication then does the work on its own, by the slide I have already followed on a GNSS spoofing hypothesis that became a fact through repetition.
The email from the crew
The most precise account came last, and from aboard. On 21 September crew members wrote to Splash247, which published their email under Sam Chambers’s byline [6]. They say they have determined that the vessel was targeted by attackers before berthing at the Italian terminal. During the transit of the Strait of Gibraltar, those attackers are said to have gained temporary control of the steam pressure and safety valve systems. Later, in the Adriatic, they are said to have compromised the tank pressure control systems and the pressure relief valves, and to have disrupted the boil-off gas management cycle. That disruption, they write, significantly increases the risk of tank rupture and explosion. The outlet states that it has not independently verified any of it.
These four claims describe a third party operating safety functions of a loaded gas carrier. The Italian authority’s description stops at the loss of cargo parameter monitoring. There is an order of magnitude between the two. No party with access to the ship has said which of the two descriptions matches what happened. The Gibraltar leg was already in circulation: the press releases of 12 September placed the ship in the strait on 2 September. When the email was written is unknown, and the order of publication says nothing about where it came from.
The answers from the owner and the equipment supplier
None of the parties involved has endorsed that account. Kongsberg Maritime supplied the ship’s positioning, navigation and propulsion systems. Its spokesman Jon Berge says the company is aware of the reports, and that it is too early to draw conclusions about the cause or any security implications. H-Line Shipping and Korean Register did not respond to requests for comment. Nobody has named an author. Vitol confirms the long-term time charter and says nothing further. No forensic result has been published, and nothing has been said of malware, of an access path or of an exploited vulnerability.
Where the ship stands
The investigations continue and the ship has still not discharged. On 21 September the tracking data place her off Barcelona at 0.8 knot, with a draught of 11.4 metres that still shows her laden [7]. Her declared destination is now Barcelona, whose estimated arrival of 20 September has passed without her berthing. The ship left Lake Charles on 20 August.

An LNG cargo evaporates continuously and the vapour produced has to be managed at all times, which puts a cost on every day spent without discharging. It comes on top of the missed delivery and the immobilisation of a 299-metre ship. Discharging at Barcelona, if it happens, will be the first move in this case that can be seen from outside.
Taking stock
A failure was reported from aboard, then recorded by an Italian authority that could not explain it, and the cargo has not arrived. The wider descriptions come from Moscow, on an unidentified source, and from seafarers who write without naming themselves. A failure of cargo monitoring aboard an LNG carrier can have a mundane origin. Nobody has ruled that out. The course to follow here is the one I argued for over a collision blamed on GNSS spoofing, waiting for the investigation report rather than imagining the facts.
A few ordinary moves would settle it. A finding from Korean Register or from the Liberian flag state would do, as would a statement from H-Line Shipping or Vitol on what failed. The terminal operator can also account for the cancelled delivery, and any party with access to the ship can confirm or deny what the crew have put into circulation.
Sources
- [1] Gas Infrastructure Europe, Inside Information Platform, urgent market message from Terminale GNL Adriatico S.r.l., 7 September 2026
- [2] gCaptain, Another Tanker Suffers Failure as Crew Suspect Cyber Attack, 18 September 2026, republication of the Bloomberg report by Weilun Soon, Ruth Liao and Charles Gorrivan
- [3] Neftegaz.RU, Кибератаки на танкеры-газовозы угрожают энергетической безопасности Европы (Cyberattacks on gas carriers threaten Europe’s energy security), 9 September 2026
- [4] EPR Network, Cyberattack on US LNG shipment takes gas reserves hostage on the eve of winter, press release issued from McKinney, Texas, 12 September 2026
- [5] PR Urgent, same text, press release issued from Florence, 14 September 2026
- [6] Splash247, Crew claims hackers seized control of LNG carrier safety systems, Sam Chambers, 21 September 2026
- [7] VesselFinder, Vivit Africa LNG, IMO 9950105, position and voyage read on 21 September 2026