On the evening of January 7, 2023, a ransomware attack struck the servers hosting DNV’s ShipManager software, one of the most widely deployed ship management platforms in the world. DNV shut the servers down immediately upon detection. The attack had already affected 70 customer organizations and approximately 1,000 vessels. For the two months it took DNV to rebuild its entire server environment from scratch, the shore-side management teams responsible for overseeing vessel operations, compliance, procurement, and crew management for those 1,000 ships were, in the formulation of Navatom’s 2026 cybersecurity analysis, “effectively blind”, unable to access crew records, maintenance histories, compliance certificates, or procurement data for the vessels under their care (Navatom, 2026; The Record, 2023). DNV is not a negligent or resource-constrained operator. It is one of the world’s largest and most respected maritime service providers. The attack worked because the attack surface it exploited, a centralized software platform serving hundreds of operators, made DNV not a target in the conventional sense but a vector: a hub through which one breach delivered simultaneous access to 1,000 spokes. Two years later, that attack has been superseded in destructive ambition and technical sophistication by the Lab Dookhtegan campaign against Iranian shipping, which compromised a satellite communications provider and, in two coordinated waves, paralyzed the communications of approximately 180 vessels simultaneously, wiping VSAT modems and severing every link between those ships and their shore-based management (Safety4Sea, 2026; Industrial Cyber, 2025a). The maritime industry is confronting a category of cyber threat that its existing regulatory frameworks, its security planning assumptions, and its vendor relationship management were not designed to address: not the hacker targeting a single vessel, but the state actor or well-resourced criminal organization that compromises the software or communications infrastructure shared by hundreds or thousands of vessels, and uses that access to impose simultaneous, fleet-scale consequences with a single operation.
The supply chain attack model that SolarWinds made famous in 2020, in which Russian SVR operatives compromised the Orion software update mechanism used by 18,000 organizations, inserting malware that gave them persistent access to the networks of every customer who installed the poisoned update, translates to the maritime domain with devastating fidelity (Panorays, 2026). The mathematics of the attack are its defining feature: the attacker invests in compromising one supplier rather than thousands of individual targets, and the supplier’s trusted relationship with its customers delivers the access the attacker needs without requiring any direct interaction with those customers at all. In maritime, the suppliers occupying this position of systemic trust include fleet management platforms whose software runs on vessels across multiple operators’ fleets, satellite communications providers whose VSAT infrastructure connects hundreds of ships to shore-based management, electronic chart and ECDIS manufacturers whose update servers push chart corrections and firmware to navigation systems fleet-wide, and OEM maintenance platforms whose remote access connections to engine and machinery control systems exist precisely to enable the vendor oversight that IACS UR E27 now mandates (CIMSEC, 2026; MarineLink, 2026).
The evolution of this attack model in maritime has followed the trajectory that MarineLink’s “Third Era” analysis documented with precision: from collateral damage in 2017 (NotPetya hitting Maersk as an unintended victim of a state-on-state wiper campaign), to deliberate hub-and-spoke targeting in 2023 (DNV ShipManager’s ransomware compromise affecting 1,000 vessels through one platform), to the 2025 model of active operational sabotage through provider-level infrastructure compromise, not merely encrypting data but destroying the physical hardware of VSAT terminals aboard ships simultaneously (MarineLink, 2026). The Lab Dookhtegan campaign against Iranian shipping is the operational expression of this third generation. Its significance is not that it affected Iranian state-owned fleets specifically. It is that it demonstrated, at operational scale, that a supplier’s infrastructure can be compromised and used to push destructive commands to every vessel in the fleet that relies on it, simultaneously, remotely, and with effects that require physical hardware replacement to reverse.
The Lab Dookhtegan Campaign: A Technical Case Study
The Lab Dookhtegan attacks on Iranian shipping in 2025 have been analyzed in sufficient technical detail by CIMSEC, Industrial Cyber, Cydome, CYTUR, and TheSign.media to provide the maritime security community with a precise operational template for what a maritime supply chain attack looks like when executed by a technically capable threat actor (CIMSEC, 2026; Industrial Cyber, 2025a; Industrial Cyber, 2025b; Cydome, 2026). The attack’s design was elegant in its simplicity: rather than attempting to compromise 116 individual vessel VSAT terminals, a target set dispersed across multiple geographic areas with varying physical access requirements, the attackers identified and compromised Fanava Group, the Iranian satellite and IT provider supplying connectivity to the National Iranian Tanker Company and Islamic Republic of Iran Shipping Lines fleets. Fanava was a single point of systemic failure: the hub through which every vessel’s communications were routed, and whose infrastructure control meant the attacker had, in effect, logical access to every ship on the network simultaneously.
The August 2025 second-wave analysis published by Cydome and documented by Industrial Cyber confirmed what the March incident had left ambiguous: “From the very beginning, this was a provider-level supply-chain attack against Fanava’s hub” (Industrial Cyber, 2025b, para. 6). The attackers had compromised Fanava’s core infrastructure rather than exploiting individual shipboard terminals, a clarification that reshaped the incident’s strategic implications entirely. The attack vectors exploited were not exotic: weak credential management and outdated firmware in the iDirect Falcon VSAT service, both of which are documented vulnerability categories in maritime SATCOM infrastructure dating back to BlackHat research presentations in 2014 and 2018 (TheSign.media, 2025). What the attackers did with their access was methodical and deliberately destructive. They wiped iDirect modems across the fleet, forcing manual reinstallation and recovery at each individual vessel, a technique specifically designed to maximize downtime and extend the period during which the fleet was severed from shore management. In the first wave, 116 vessels were affected. In the second wave, the campaign expanded to include 39 NITC tankers and 25 IRISL cargo ships simultaneously (TheSign.media, 2025). The CIMSEC analysis captured the strategic implication with precision: “Compromise of one provider delivered access to 116 vessels simultaneously. Understanding the security posture of these suppliers — and the potential for similar attacks against providers serving allied commercial fleets — supports broader maritime domain awareness” (CIMSEC, 2026, para. 9).
The qualification “allied commercial fleets” in the CIMSEC analysis is the sentence that every Western maritime operator should be reading carefully. The Lab Dookhtegan campaign was executed against Iranian state-owned vessels by a hacktivist group with anti-Iranian motivations. The attack architecture it employed is not specific to Iranian shipping, to state-owned fleets, or to any particular political context. It is specific to the model of centralized satellite provision, fleet management software, and OEM remote access that characterizes virtually every modern commercial fleet regardless of flag state or ownership structure. The CYTUR 2026 White Paper’s assessment of the supply chain threat is direct: “The tactic of disabling an entire fleet by infiltrating a single satellite provider, as seen in the Lab Dookhtegan case, is likely to become more common” (Industrial Cyber, 2026). More specifically, CYTUR identified attacks through software and communication service providers as representing “one of the highest-impact vectors,” with attackers able to “distribute malicious code simultaneously to tens of thousands of vessels worldwide that utilize the compromised software” by implanting malware into OEM update servers or management tools (Safety4Sea, 2026).
The maritime software ecosystem contains several categories of platforms whose architecture creates the systemic concentration of trust that supply chain attacks require. Fleet management software — ShipManager and its competitors in the planned maintenance, procurement, crew management, and compliance reporting domains — runs on a centralized server infrastructure to which individual vessels connect for data synchronization, update delivery, and compliance reporting. The DNV incident established that ransomware penetrating this infrastructure imposes simultaneous operational blindness on every operator using the platform, regardless of the individual security posture of the vessels themselves (Navatom, 2026; Riviera Maritime Media, 2023). The Navatom analysis of the DNV incident identifies the specific vulnerability that hub-and-spoke architecture creates: “your ship management software is your primary attack surface”, a formulation that reflects the operational reality that vessels running ShipManager, or any equivalent platform, are dependent on the platform’s availability and integrity for the compliance, maintenance, and operational functions that their crews and shore management teams perform daily (Navatom, 2026, para. 3).
VSAT providers represent the second, and more immediately dangerous, attack-surface category. Unlike fleet management software, whose compromise disrupts administrative functions while vessels remain operationally capable, VSAT compromise severs the communications infrastructure on which modern vessel operations depend for weather routing, port authority communications, cargo management coordination, and the real-time situational awareness that safety management systems increasingly require. The iDirect Falcon platform that Lab Dookhtegan exploited is not an obscure Iranian state system. It is a globally deployed commercial VSAT service used by commercial fleets across multiple jurisdictions. TheSign.media’s analysis of the SATCOM vulnerability landscape documented that researchers had demonstrated in 2018 how “entire fleets could be compromised via weaknesses in VSAT providers”, and that the Lab Dookhtegan campaign confirmed those vulnerabilities remained exploitable seven years later despite the intervening period of industry awareness (TheSign.media, 2025). The October 2025 ransomware attack on FURUNO Electric, which froze maintenance updates and spare parts supply for the Japanese radar and ECDIS manufacturer’s global installed base, creating what CYTUR described as a “safety vacuum” across fleets dependent on its chart correction and firmware update services, demonstrated that OEM equipment manufacturers occupy the same position of systemic trust as VSAT providers and fleet management platform vendors (Splash247, 2026).
The USCG’s July 2025 cybersecurity final rule represents the most comprehensive mandatory framework the U.S. maritime sector has operated under, requiring incident reporting, Cybersecurity Officer designation, and the submission of formal Cybersecurity Plans by July 2027. The IACS UR E27 requirement, extending cyber resilience standards to OEM equipment manufacturers for newbuilds contracted after July 2024, addresses the hardware supply chain dimension at the component level. Both frameworks represent genuine regulatory progress. Neither framework directly addresses the specific vulnerability documented in the Lab Dookhtegan and DNV ShipManager incidents: the absence of mandatory third-party software vendor security vetting requirements for the fleet management, VSAT, and OEM platform relationships that create systemic fleet-level exposure (Ship Universe, 2026; Navatom, 2026). The USCG rule requires operators to develop a Cybersecurity Plan. It does not require that the plan include a Supply Chain Risk Management program specifying how operators assess the security posture of platform vendors, VSAT providers, and OEM maintenance systems whose compromise would simultaneously affect every vessel in the fleet. Ship Universe’s regulatory breakdown characterizes this as the gap that separates compliance from genuine security: “what marine underwriters and operators need to address is the security posture of their suppliers — and the USCG rule’s current framework leaves this to operator discretion rather than establishing minimum standards” (Ship Universe, 2026, para. 5).
The Navatom analysis identifies the operational question that every maritime operator should be asking about their fleet management platform relationship: does the vendor support the access controls, audit trails, incident response logging, and third-party vendor oversight that a credible Information Security Management System requires? If the answer is no, and for many legacy fleet management platforms, it is, the gap is not merely a regulatory compliance issue but an operational exposure that no amount of vessel-level security investment can close (Navatom, 2026). A vessel with hardened onboard systems, IACS E26-compliant network segmentation, and a fully trained crew that follows every BMP Maritime Security and USCG cybersecurity protocol is still exposed to simultaneous compromise if the fleet management platform its systems synchronize with is breached at the vendor level.
The CIMSEC analysis of the Lab Dookhtegan attack identified the three operational requirements for genuine maritime supply chain security with the clarity that only post-incident analysis enables: supply chain assessment for every VSAT provider, navigation system manufacturer, and vessel management software company in the operator’s ecosystem; information sharing mechanisms that allow lessons learned from individual incidents to reach other operators before they become victims; and a fundamental shift in how operators conceptualize their security perimeter, from the vessel boundary to the full ecosystem of trusted software and communications relationships that connect the vessel to the outside world (CIMSEC, 2026).
The practical implementation of supply chain security in maritime starts with an inventory that most operators have not completed: a comprehensive mapping of every software platform, communications provider, OEM remote access relationship, and third-party data service that connects to the vessel’s systems, directly or through the shore management infrastructure. Each entry in this inventory represents a potential supply chain attack vector whose security posture the operator cannot control but must assess. Asking the ten questions that Navatom identifies as the minimum vendor security assessment for a cloud-connected fleet management platform, covering architecture, access controls, incident response capability, audit trail retention, and third-party vetting of the vendor’s own suppliers, provides the baseline intelligence needed to make risk-informed decisions about which platform relationships to maintain, which to restructure, and which to replace (Navatom, 2026). The Panorays 2026 supply chain attack analysis documents the specific technical indicators that distinguish a vendor with genuine supply chain security capability from one performing compliance theater: software composition analysis that identifies vulnerable open-source components before they are exploited, Software Bill of Materials documentation that establishes exactly what code is running in every update, and verified multi-party code signing that makes unauthorized update injection detectabl (Panorays, 2026).
The AI-acceleration dimension of the vulnerability window compounds the urgency of this assessment. CYTUR’s 2026 White Paper documented that adversaries can now weaponize newly discovered software vulnerabilities within 48 hours of their public disclosure, a window shorter than the update and patch cycles of virtually every fleet management platform and VSAT firmware in commercial operation (Industrial Cyber, 2026). In the maritime supply chain context, this means that a zero-day vulnerability in a fleet management platform’s authentication mechanism can be exploited across every vessel the platform serves before the vendor has had time to develop, test, and deploy a patch. The operational consequence for maritime operators is that the traditional patch-and-monitor security model, which identifies a vulnerability, waits for the vendor to release a fix, deploys the fix, and confirms resolution, is no longer adequate for the threat tempo that AI-enabled adversaries have established. Real-time monitoring of vendor infrastructure for anomalous behavior patterns, network segmentation that limits the blast radius of a compromised update, and incident response plans that include “vendor compromise” as an explicitly modeled scenario are the minimum requirements for a security posture that matches the current threat.
The maritime industry has spent the post-2017 decade building vessel-level cybersecurity capabilities, training crews, hardening OT networks, implementing BMP guidance, and working toward IACS and USCG regulatory compliance. This investment is necessary and has produced measurable improvements in the security posture of individual vessels. It is also, as the Lab Dookhtegan and DNV ShipManager incidents demonstrate with operational clarity, insufficient, because the threat has moved upstream. The attacker who compromises a fleet management platform vendor, a VSAT provider, or an OEM firmware update server does not need to engage with the vessels whose security posture has been hardened. They need only to poison the source from which those vessels receive their software, their communications, and their operational data. The DNV incident blinded 1,000 vessels for two months through one ransomware attack on one server environment. The Lab Dookhtegan campaign severed communications across 180 ships in two waves by compromising one satellite provider’s hub. CYTUR projects that this model will become more common, not less, as AI tools enable adversaries to weaponize vulnerabilities at a pace that individual operator security programs cannot match. The maritime industry’s regulatory frameworks are catching up to vessel-level threats. They have not yet caught up to the supply chain threat posed by the 2023 and 2025 incidents, as documented in operational detail. Closing that gap requires treating every vendor relationship as a potential attack vector, assessing the security posture of every platform that connects to the fleet, and recognizing that the most dangerous point of entry into a maritime network is not the ship. It is the software that the ship trusts.
CIMSEC — Center for International Maritime Security. (2026, March 23). The unwitting fleet. https://cimsec.org/the-unwitting-fleet/
Cydome. (2026). Maritime cyber trends report 2026: Fleet-wide cyberattack exposes VSAT vulnerabilities. https://industrialcyber.co/transport/cydome-report-finds-150-surge-in-maritime-ot-cyberattacks-as-ransomware-tightens-grip-in-2025/
Industrial Cyber. (2025a, February 24). Maritime cyber incidents jump 103%, as CYTUR warns smart ships under fire. https://industrialcyber.co/reports/maritime-cyber-incidents-jump-103-as-cytur-warns-smart-ships-under-fire-urges-secure-by-design-overhaul/
Industrial Cyber. (2025b, September 2). Lab Dookhtegan cyberattack on Iranian oil tankers traced to supply chain compromise of Fanava’s infrastructure. https://industrialcyber.co/supply-chain-security/lab-dookhtegan-cyberattack-on-iranian-oil-tankers-traced-to-supply-chain-compromise-of-fanavas-infrastructure/
Industrial Cyber. (2026, March 4). Cydome report finds 150% surge in maritime OT cyberattacks as ransomware tightens grip in 2025. https://industrialcyber.co/transport/cydome-report-finds-150-surge-in-maritime-ot-cyberattacks-as-ransomware-tightens-grip-in-2025/
MarineLink. (2026, March 9). Navigating the “Third Era” of maritime cyber risk. https://www.marinelink.com/news/navigating-third-era-maritime-cyber-risk-536724
Maritime Executive. (2026, February 24). Report: Maritime cyberattacks doubled in 2025. https://maritime-executive.com/article/report-maritime-cyberattacks-doubled-in-2025
Navatom. (2026, April 3). Maritime cybersecurity 2026: Ship manager’s guide. https://navatom.com/blog/maritime-cybersecurity-2026-ship-managers-guide
Panorays. (2026, April 13). Cyber security supply chain attacks: Navigating the 2026 threat landscape. https://panorays.com/blog/cyber-security-supply-chain-attacks/
Riviera Maritime Media. (2023). DNV: “All users back online” two months after ShipManager cyber attack hit 1,000 vessels. https://www.rivieramm.com/news-content-hub/news-content-hub/dnv-reports-cyber-attack-on-its-shipmanager-software-74466
Safety4Sea. (2026, February 24). Maritime cyber incidents jumped 103% in 2025. https://safety4sea.com/maritime-cyber-incidents-jumped-103-in-2025/
Ship Universe. (2026). 2026 maritime cybersecurity regulations: A simplified breakdown. https://www.shipuniverse.com/2025-maritime-cybersecurity-regulations-a-simplified-breakdown/
Splash247. (2026, February 23). Maritime cyber incidents doubled last year. https://splash247.com/maritime-cyber-incidents-doubled-last-year/
The Record / Recorded Future News. (2023, January 9). Ransomware attack on maritime software impacts 1,000 ships. https://therecord.media/ransomware-attack-on-maritime-software-impacts-1000-ships
TheSign.media. (2025, September 6). SATCOM under fire: The Lab Dookhtegan attack on Iranian fleets. https://www.thesign.media/blog/satcom-under-fire-the-lab-dookhtegan-attack-on-iranian-fleets