Cyber Attack on National Tanker Company Disrupts Iranian Merchant Ship Communications

A major cyberattack has disrupted the communications of dozens of Iranian merchant vessels. A hacker group calling itself Lab-Dookhtegan has claimed responsibility for the operation.

Hackers hit Iran’s shipping networks

Reports say the attack disabled ship-to-shore communication systems of 39 oil tankers and 25 cargo ships operated by the National Iranian Tanker Company (NITC) and the Islamic Republic of Iran Shipping Lines (IRISL).

So far, NITC and IRISL have not confirmed problems. Cyber experts studied the claims and found them credible. They believe the hackers targeted ship communication networks.
This caused a large disruption in the systems.

Lab-Dookhtegan has launched similar attacks before. In March, it claimed to disable communications on over 100 ships. These ships were linked to the same two Iranian companies. That attack happened during military operations in Yemen. Observers see the group as part of a wider campaign. The campaign seems to target Iranian shipping activities.

How the hackers broke into systems

The hackers targeted Fanava Group, a private IT firm in Tehran. Fanava provides internet and satellite services for ships. It also runs networks used by merchant vessels.
The company operates a cybersecurity system called Falcon. Hackers claim they broke into this system.

The hackers broke into these systems. They blocked ship-to-shore communications.
They also disrupted AIS tracking. AIS helps ships share their location and movements.
Ports and coastal authorities use this information. Without AIS, it is harder to track ships.
This creates serious risks for safe navigation.

How Cyber Attacks on Industrial Control Systems Can Endanger Lives ?

Although little is known about Lab-Dookhtegan itself, the group seems to focus on Iranian targets. Cybersecurity experts have examined the techniques used in this latest attack and judged them as credible. An Israeli maritime cybersecurity company has stated that the tactics matched known cyber warfare methods.

Fanava, the company targeted in the attack, runs satellite networks and even financial services in Iran. Despite its central role in these sectors, the company does not currently appear on sanctions lists maintained by the US, UK, or EU. This makes the targeting of its systems particularly sensitive, as it highlights how companies not directly under sanctions can still be drawn into the conflict surrounding Iranian oil and shipping.

Growing pressure on Iran’s shipping activities

Iran’s shipping sector has long been under scrutiny because of international sanctions related to oil exports. In recent months, both the United States and the United Kingdom have expanded their enforcement to include not just ships, but also service providers linked to Iranian oil trade.

While US authorities have been aggressive in issuing fines and penalties for sanctions breaches, the UK has faced criticism for weak enforcement. Reports note that US regulators imposed hundreds of millions of dollars in fines this year alone, while UK authorities have taken only a few actions, none of them linked to Iranian oil.

Insider revenge cyberattack freezes 1,000 workers — Eaton hit with massive disruption and losses

Enforcement is a major challenge because of the complex networks Iran’s shipping activities rely on. These networks often use front companies, hidden ownership, and offshore service providers to avoid detection.

The latest hacking incident shows how Iran’s shipping operations remain exposed to both sanctions enforcement and cyber operations.

Renuka Bangale
Renuka Bangale
Renuka is a distinguished Chartered Accountant and a Certified Digital Threats Analyst from Riskpro, renowned for her expertise in cybersecurity. With a deep understanding of cybercrimes, malware, cyber warfare, and espionage, she has established herself as an authority in the field. Renuka combines her financial acumen with advanced knowledge of digital threats to provide unparalleled insights into the evolving landscape of information security. Her analytical prowess enables her to dissect complex cyber incidents, offering clarity on risks and mitigation strategies. As a key contributor to Newsinterpretation’s information security category, Renuka delivers authoritative articles that educate and inform readers about emerging threats and best practices.

TOP 10 TRENDING ON NEWSINTERPRETATION

Pakistan linked APT36 uses fake PDF files to spread Linux malware in attacks on Indian government

Fake PDF files hide dangerous malware A hacker group called...

Johnson and Johnson unit ends two year legal battle on Skin360 app storage of biometric information

Johnson & Johnson’s former consumer products unit has agreed...

Ghislaine Maxwell recalls Musk encounters, denies Trump ties in explosive court record

Ghislaine Maxwell, once known for her close ties to...

Netflix scores historic first box office crown as KPop Demon Hunters hits $18M in two days

Netflix has claimed its first North American weekend box...

PayPal denies breach after hacker claims leak of 15.8 million credentials on dark web

In mid-August 2025, panic spread online after a hacker...

Colt continues forensic review after ransomware attack hits customer-facing systems

Colt, an industrial technology company, has confirmed a ransomware...

Orange confirms ransomware breach with 4 GB of customer data exposed on dark web

A major cyberattack has hit Orange, one of the...

Watch ‘F1: The Movie’ online today on Prime Video and Apple TV

The wait is over for fans of high-speed action...

Uzbekistan Airways hack exposes 300 GB data of passengers and U.S. government employees

A hacker has claimed responsibility for stealing a massive...

DOJ drops explosive Maxwell transcripts — critics slam her as a “known liar”

The Trump administration has released transcripts from two days...

Related Articles

Popular Categories

error: Content is protected !!