Maritime cybersecurity firm Cydome has warned that disabling a vessel’s Automatic Identification System (AIS) while transiting high-risk waters like the Strait of Hormuz does not conceal the ship’s location, as satellite communications equipment continues to expose its position electronically.
The company has published an advisory document following a surge in reported AIS blackouts across the Persian Gulf, amid concern around vessels that appear to vanish from tracking systems. Cydome says that relying on AIS deactivation without securing satellite gateways could leave a vessel exposed to tracking and targeting via its VSAT signature.
The company’s cyber research team found that maritime VSAT infrastructure operating around the Strait of Hormuz was extensively exposed, with management interfaces openly accessible from the internet using default configurations.
“While deactivating tracking is a recognised safety measure in high-risk zones, it does not silence the ship’s broader digital footprint, which could also disclose its location,” said Nir Ayalon, co-founder and Chief Executive Officer, Cydome.
“Risk reduction must be approached through the lens of digital hygiene, minimising the discoverability of these background systems to ensure the vessel’s digital shadow does not provide a roadmap for adversaries.”
“Many ship operators are not aware that the location remains publicly visible through the VSAT satellite communications devices which, unlike AIS, maintain continuous, internet-connected links between ship and shore.”
The research also highlights that an exposed VSAT interface can serve as an entry point to onboard systems. As maritime communication hardware is often networked with onboard Operational Technology (OT), a vulnerability at the satellite gateway could open a path for unauthorised access to navigation, propulsion, and power management controls where network architecture is not segregated.
Cydome points to events in 2025 in which the hacktivist group Lab Dookhtegan disrupted the communications of 116 tankers linked to companies affiliated with Iran, with VSAT exposure providing both the reconnaissance surface and the attack vector.
“When a crew disables AIS to avoid detection, the VSAT terminal keeps on transmitting. The ship is invisible to coastal AIS stations, but the location remains visible to anyone with the right tools and knowledge of what to look for,” adds Mr Ayalon.
“This is not a vulnerability, but an actual design feature. Unfortunately, many operators are not aware of such risks and leave the ships exposed.”
The full report can be accessed here.



