The U.S. Coast Guard and FBI are investigating suspected cyberattacks against at least two foreign tankers bound for the United States, according to Bloomberg.
Specialized teams boarded the vessels in the Gulf of Mexico in August after indications that their networks had been compromised by foreign cyber actors, examining both operational technology and information technology systems and working with crews to remove potential threats.
One of the vessels has been identified as the VL Prosperity, a very large crude carrier capable of transporting roughly 2.3 million barrels of oil. The tanker was reportedly attacked while traveling through the Strait of Gibraltar in early August and lost communications for more than 30 hours. U.S. authorities boarded the vessel on August 21. A second tanker targeted in a separate cyberattack was boarded on August 24 for a similar assessment.
The Coast Guard and FBI said there have been no reported operational disruptions, vessel instability, physical danger to crews or environmental impacts.
John Strand, Owner, Black Hills Information Security, Inc.:
“There’s a lot of conversation right now about attacks against operational technology, especially water and power systems, given the current geopolitical climate. But tankers are absolutely on the menu as well. What makes these environments so attractive is that much of this technology doesn’t have the same endpoint security you would expect on a Windows 11 workstation. You often don’t have EDR running on these systems. That creates a rich target for attackers because many of the defensive technologies we’ve come to rely on in traditional IT simply aren’t there.”
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“It appears two separate claims are circulating, and they’re being treated as one. The first one is from the Coast Guard, which has acknowledged indications that the vessel’s network was compromised, with no reported operational disruptions. The other comes from Iranian media, citing a single unnamed crew member, which has alleged a much more extensive compromise involving cooling, fuel systems, and other critical elements of the vessel. Those claims have not been independently verified as of yet, so it’s important to keep your skeptical hat on. Additionally, it’s important to note that Iranian media reporting on the incident also does not establish Iranian responsibility; attribution remains unresolved.
“Regardless, this is a significant situation. A suspected compromise aboard a tanker warrants serious attention even if propulsion and other critical systems continued operating normally. The fact that the Coast Guard and FBI deployed their cyber teams to assess the vessel and remove potential threats shows the importance, even if it does not validate the more dramatic claims.
“The reported communications outage raises a separate technical question. A compromise of the communications suite, or plain RF interference, could explain a 30-hour outage without a threat actor ever touching the ship’s controls. GPS receivers and satellite terminals are chronically soft targets, and I spent enough of my military career working through degraded and jammed satellite comms to know how ordinary that failure mode is. The Strait of Gibraltar in particular is a well-documented GNSS interference corridor, so that’s a possibility I’d want investigators to rule in or out early, but an outage on its own still tells you nothing about how far an intrusion actually reached.
“I think if we take anything away from this ordeal, it is that nothing came of this compromise. No major disruption, environmental impact, or danger to the crew, and if a threat actor genuinely had control of propulsion on a fully loaded crude carrier, the obvious question is why nothing was done with it. When I’ve seen this pattern in the past, it usually points to a proof-of-concept or recon attack, more colloquially put, a rehearsal, not a performance. Now, a rehearsal for what? Can’t say, and neither can anyone else right now, but that’s for the investigators to work out. Either way, with global oil supply already at its tightest it’s been in modern history, this isn’t a low-consequence practice run.”
Damon Small, Board of Directors, Xcape Inc.:
“Physical maritime operations and global energy supply chains face severe operational risks when shipboard networks are compromised. Contrary to official statements downplaying the event, a 30-hour communications blackout on a crude carrier is a significant operational disruption. Vessels underway depend heavily on continuous communications for navigation and collision avoidance, meaning an unannounced blackout can easily precipitate a maritime disaster. Modern commercial watercraft rely on multi-channel connectivity including Very Small Aperture Terminal (VSAT), cellular, and Wi-Fi systems, making a sustained blackout indicative of critical bridge system failure. Defenders must strictly segment bridge communication links from physical operational technology domains, audit firmware across satellite hardware, and monitor for anomalous signal degradation.
“Critical Takeaways
- Communication loss directly compromises vessel navigation, making a multi-hour blackout a primary operational threat rather than a minor IT glitch.
- Reliance on VSAT, cellular, and Wi-Fi links requires strict logical separation to prevent lateral movement into shipboard control systems.
- Maritime operators must treat satellite communications and bridge telemetry as mission-critical assets requiring continuous anomaly monitoring.
“Calling a 30-hour communication blackout on a crude carrier non-disruptive is like ignoring a broken ship’s wheel because the horn still works.”
It seems like threat actors may have found a new hunting ground. That is bad news for all of us.
OT security market projected to quadruple as critical infrastructure threats grow
Posted in Commentary with tags OT Securiity on September 16, 2026 by itnerdThe global operational technology (OT) security market is projected to grow from $44.34 billion in 2025 to $178.93 billion by 2035, according to new research from SNS Insider, representing an annual growth rate of nearly 15%.
The growth is being driven by increasing cyberattacks against critical infrastructure and industrial control systems, along with the rapid adoption of industrial IoT, smart manufacturing and increasingly interconnected IT and OT environments.
Power, transportation, manufacturing, energy and utilities are among the sectors increasing investment in technologies designed to protect mission-critical operational systems. North America accounted for approximately 42% of the global OT security market in 2025.
Security solutions, including threat detection, monitoring, vulnerability management and incident response, represented nearly 72% of the market in 2025. Managed and professional security services are expected to be the fastest-growing segment as organizations seek additional expertise to secure increasingly complex industrial environments.
Denis Calderone, CTO, Suzu Labs:
“The projected growth tracks with what we’ve been living through lately. The last several months have been a steady stream of attacks on operational technology, from Iran-linked activity against water and fuel-monitoring systems to the wave of PLC compromises that had water utilities scrambling this summer. When CISA is telling the entire water sector to pull PLCs off the public internet and the FBI is documenting lost pressure and actual flooding, budgets catching up to the threat isn’t hype, it’s just an inevitable fact.
“We strongly suspect that the speed in growth of these types of attacks are likely in line with the increased use of offensive AI. The August advisory from NSA, CISA, the FBI, DOE, and EPA on Siemens S7 controllers spelled it out pretty clearly. Attackers are using AI-generated scripts, dressed up to look like legitimate monitoring tools, to build working ICS capability with far less expertise and in far less time than this used to take. That compresses the learning curve that used to keep casual actors out of OT, which means more people can credibly threaten these environments. Executive Order 14306 last summer named this directly, calling out China, Iran, and others targeting critical infrastructure and steering federal cyber efforts toward AI-era threats. The forecast is really just the market responding to conditions.”
Damon Small, Board of Directors, Xcape Inc.:
“Rapidly converging IT and operational technology (OT) environments expose legacy industrial control systems to direct cyber risks, threatening revenue, physical safety, and operational continuity. Driven by aggressive digital transformation across power, manufacturing, and utilities, this market expansion highlights a growing operational vulnerability rather than simple tech adoption. Paradoxically, investment in OT security is surging alongside rising cybersecurity unemployment, revealing a structural mismatch: the skilled, experienced professionals required to protect complex physical assets remain scarce. Because legacy control systems frequently lack basic authentication controls, traditional perimeter security fails. To bridge this acute talent gap and secure legacy assets, security leaders must deploy AI-assisted tooling, enforce strict network segmentation between IT and OT domains, and mandate strong access governance for third-party maintenance connections.
Critical Takeaways
“If your OT security strategy relies entirely on hiring unicorns, prepare to explain your next outage to the board using hand puppets.”
Doc McConnell, Head of Policy and Compliance, Finite State:
“Until recently, operational technology was considered a niche specialty within the field of cybersecurity. A market projection like this shows that’s no longer the case.
“There are two drivers for this rapid expansion. First, we’re increasingly seeing adversaries targeting operational technology. In April, CISA, the FBI, and EPA warned that Iran-linked actors were reaching programmable logic controllers at U.S. water and energy utilities, and in July the FBI documented attackers changing addresses, passwords, and ladder logic on internet-exposed PLCs at water systems in at least seven states. These attacks have had real operational consequences, including pressure loss and flooding.
“And second, we’re seeing a trend toward OT protection in US policy. Last month’s executive order on bulk-power supply chain security puts the origin and security of grid equipment under federal scrutiny, and the Water Cyber Shield Act proposed in Congress would direct EPA to set tiered security standards for drinking water and wastewater systems.
“But OT operators can’t wait for policy to catch up, which is why we’re seeing particular growth in the services segment. Buying new security tooling is straightforward. Finding people who understand how a control system actually behaves, and who can build security into equipment without risking downtime or disruption is harder. In these environments, interruption in service is a life-safety issue, so that expertise is worth hiring for.”
The time to spend is now. Because it is a matter of when and not if you will get attacked.
Leave a comment »