Fanava
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
Fanava is an Iranian company operating in the satellite communications sector, providing connectivity solutions that link maritime vessels with onshore infrastructure. The organisation functions as a satcom provider, delivering ship-to-shore voice over IP (VOIP) services used by Iranian commercial shipping operators. Its role in the maritime telecommunications supply chain positioned it as a critical intermediary for fleet communications, enabling tankers and other vessels to maintain contact with home offices and port authorities while operating at sea.
The scale of Fanava's operations is most clearly illustrated by the breadth of its customer base within Iran's state-owned shipping sector. The company provided fleetwide communications services for vessels operated by the National Iranian Tanker Company (NITC) and the Islamic Republic of Iran Shipping Lines (IRISL), indicating that its services supported a significant portion of Iran's sanctioned tanker fleet. This reach meant that disruptions to Fanava's infrastructure could cascade across multiple major shipping entities, amplifying the impact of any security incident affecting its network.
A distinguishing attribute of Fanava is its specialisation in maritime satellite communications within a tightly regulated market. Operating under Iranian jurisdiction, the company serves clients operating in a sector subject to extensive international sanctions, which likely shaped its role as a domestic connectivity provider for state-affiliated maritime operators. Its technical competency in remote vessel communications made it a single point of dependency for ship-to-shore voice services, as demonstrated by the fact that an attack on its systems required physical hardware replacement of onboard modems before connectivity could be restored. This dependency highlights both the technical importance of Fanava's infrastructure and the concentration of risk inherent in relying on a single domestic provider for critical maritime communications.
The most significant documented incident involving Fanava occurred at the beginning of 2025, when the threat group "Lab Dookhtegan" executed a supply chain cyberattack against the company. By penetrating Fanava's systems, the attackers obtained fleetwide control over the VOIP services used by Iranian state-owned tankers. During the intrusion, the group exfiltrated corporate documents belonging to NITC and IRISL, which were subsequently released publicly. After achieving their objectives, the attackers destroyed the vessels' modems by overwriting partitioned memory, rendering the hardware inoperable and forcing affected tankers to depend on alternative communication methods with their home offices and port authorities until physical replacements could be installed. The incident underscored Fanava's structural position as a key node in Iran's maritime communications ecosystem and the vulnerabilities that arise when critical connectivity services are concentrated within a single provider subject to targeted cyber operations.
Incidents
1 incident linked to this organisation.