Two oil tankers traveling toward the United States were subjected to cyber incidents that disrupted onboard systems, prompting the US Coast Guard and FBI to investigate the vessels after they reached the Gulf of Mexico.
US officials cited in reports said Coast Guard and FBI personnel boarded both ships last month as investigators examined possible malicious activity affecting the vessels. Authorities have not publicly attributed the incidents to Iran or confirmed who was behind the attacks.
VL Prosperity Among Vessels Investigated
One of the tankers, the VL Prosperity, is a Liberian-flagged crude oil carrier that departed Egypt on August 1 and was headed for Galveston, Texas.
An Iranian news report published on August 20 claimed the vessel experienced a cyber intrusion on August 7 while sailing through the Strait of Gibraltar. The report, citing a crew member, alleged that the incident affected several operational systems, including equipment associated with the engine room, fuel delivery and cooling.
The same report claimed that navigation and cargo-related systems were also accessed and that communications were unavailable for approximately 30 hours. These claims have not been independently confirmed by US authorities.
Coast Guard and FBI Spend Four Days Aboard
A day after the Iranian report appeared, a team involving Coast Guard cyber specialists, law enforcement personnel, a vessel inspector and members of the FBI Cyber Action Team boarded the VL Prosperity.
The team reportedly remained aboard for four days while examining the ship’s information technology infrastructure and other systems.
The second tanker was inspected on August 24, according to reporting by The Wall Street Journal. Both vessels were boarded after reaching the Gulf of Mexico.
Investigators Confirm Malicious Cyber Activity
Rear Adm. Amy Grable, commander of the Coast Guard Cyber Command, told CBS News that investigators identified evidence indicating the presence of a malicious cyber actor after examining the tanker’s IT environment and other onboard systems.
However, the Coast Guard has not publicly connected the activity to Iran.
Grable also said investigators did not discover anything during the inspection that indicated the tanker was unsafe to operate. She described the operation as part of a broader cybersecurity effort, noting that Coast Guard Cyber Protection Teams had conducted an estimated 40 to 50 similar vessel boardings during the preceding year.
Experts Warn Against Overestimating Remote Ship Control
Quinton DuBose, a former Coast Guard cyber official, said the biggest concern may not necessarily be an attacker gaining complete control of a large tanker.
Instead, he suggested that an adversary could compromise several individual systems and gradually interfere with operations to the point where maintaining safe navigation becomes difficult.
Investigators are still determining whether the two incidents are connected and whether a government-backed group was involved. DuBose also urged caution when assessing claims made in Iranian media about the sophistication of the alleged attack.
Maritime Industry Faces Growing Cyber Risks
The incidents highlight broader cybersecurity concerns across the global maritime industry. Ships increasingly depend on connected operational technology, satellite communications and other digital systems, creating additional potential entry points for attackers.
Cybersecurity specialists have warned that weaknesses involving wireless networks, satellite communications, radio systems, connected devices and removable media can expose vessels to cyber threats.
A successful attack does not necessarily require complete control of a ship. Disrupting individual systems, interfering with communications or manipulating navigation data could create significant operational challenges.
New Coast Guard Cybersecurity Office
The developments came shortly after the US Coast Guard announced the establishment of an Office of Maritime Cybersecurity Policy. The office is intended to serve as a central authority for developing and implementing cybersecurity policies covering the US marine transportation system.
The move reflects growing concern over the potential economic impact of cyberattacks against ships, ports and maritime supply chains.
With a large share of international trade transported by sea, major disruptions to maritime operations could have consequences well beyond individual vessels, potentially affecting cargo movement and supply chains.
For now, the investigations into the two tanker incidents remain ongoing. Authorities have not publicly identified the attacker, established a connection between the cases or confirmed Iran’s involvement.