The U.S. Coast Guard and FBI are investigating suspected cyberattacks against at least two foreign tankers bound for the United States, according to Bloomberg.
Specialized teams boarded the vessels in the Gulf of Mexico in August after indications that their networks had been compromised by foreign cyber actors, examining both operational technology and information technology systems and working with crews to remove potential threats.
One of the vessels has been identified as the VL Prosperity, a very large crude carrier capable of transporting roughly 2.3 million barrels of oil. The tanker was reportedly attacked while traveling through the Strait of Gibraltar in early August and lost communications for more than 30 hours. U.S. authorities boarded the vessel on August 21. A second tanker targeted in a separate cyberattack was boarded on August 24 for a similar assessment.
The Coast Guard and FBI said there have been no reported operational disruptions, vessel instability, physical danger to crews or environmental impacts.
John Strand, Owner, Black Hills Information Security, Inc.:
“There’s a lot of conversation right now about attacks against operational technology, especially water and power systems, given the current geopolitical climate. But tankers are absolutely on the menu as well. What makes these environments so attractive is that much of this technology doesn’t have the same endpoint security you would expect on a Windows 11 workstation. You often don’t have EDR running on these systems. That creates a rich target for attackers because many of the defensive technologies we’ve come to rely on in traditional IT simply aren’t there.”
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“It appears two separate claims are circulating, and they’re being treated as one. The first one is from the Coast Guard, which has acknowledged indications that the vessel’s network was compromised, with no reported operational disruptions. The other comes from Iranian media, citing a single unnamed crew member, which has alleged a much more extensive compromise involving cooling, fuel systems, and other critical elements of the vessel. Those claims have not been independently verified as of yet, so it’s important to keep your skeptical hat on. Additionally, it’s important to note that Iranian media reporting on the incident also does not establish Iranian responsibility; attribution remains unresolved.
“Regardless, this is a significant situation. A suspected compromise aboard a tanker warrants serious attention even if propulsion and other critical systems continued operating normally. The fact that the Coast Guard and FBI deployed their cyber teams to assess the vessel and remove potential threats shows the importance, even if it does not validate the more dramatic claims.
“The reported communications outage raises a separate technical question. A compromise of the communications suite, or plain RF interference, could explain a 30-hour outage without a threat actor ever touching the ship’s controls. GPS receivers and satellite terminals are chronically soft targets, and I spent enough of my military career working through degraded and jammed satellite comms to know how ordinary that failure mode is. The Strait of Gibraltar in particular is a well-documented GNSS interference corridor, so that’s a possibility I’d want investigators to rule in or out early, but an outage on its own still tells you nothing about how far an intrusion actually reached.
“I think if we take anything away from this ordeal, it is that nothing came of this compromise. No major disruption, environmental impact, or danger to the crew, and if a threat actor genuinely had control of propulsion on a fully loaded crude carrier, the obvious question is why nothing was done with it. When I’ve seen this pattern in the past, it usually points to a proof-of-concept or recon attack, more colloquially put, a rehearsal, not a performance. Now, a rehearsal for what? Can’t say, and neither can anyone else right now, but that’s for the investigators to work out. Either way, with global oil supply already at its tightest it’s been in modern history, this isn’t a low-consequence practice run.”
Damon Small, Board of Directors, Xcape Inc.:
“Physical maritime operations and global energy supply chains face severe operational risks when shipboard networks are compromised. Contrary to official statements downplaying the event, a 30-hour communications blackout on a crude carrier is a significant operational disruption. Vessels underway depend heavily on continuous communications for navigation and collision avoidance, meaning an unannounced blackout can easily precipitate a maritime disaster. Modern commercial watercraft rely on multi-channel connectivity including Very Small Aperture Terminal (VSAT), cellular, and Wi-Fi systems, making a sustained blackout indicative of critical bridge system failure. Defenders must strictly segment bridge communication links from physical operational technology domains, audit firmware across satellite hardware, and monitor for anomalous signal degradation.
“Critical Takeaways
- Communication loss directly compromises vessel navigation, making a multi-hour blackout a primary operational threat rather than a minor IT glitch.
- Reliance on VSAT, cellular, and Wi-Fi links requires strict logical separation to prevent lateral movement into shipboard control systems.
- Maritime operators must treat satellite communications and bridge telemetry as mission-critical assets requiring continuous anomaly monitoring.
“Calling a 30-hour communication blackout on a crude carrier non-disruptive is like ignoring a broken ship’s wheel because the horn still works.”
It seems like threat actors may have found a new hunting ground. That is bad news for all of us.
Related
This entry was posted on September 16, 2026 at 4:25 pm and is filed under Commentary with tags FBI. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Coast Guard and FBI board two U.S.-bound tankers after suspected cyberattacks
The U.S. Coast Guard and FBI are investigating suspected cyberattacks against at least two foreign tankers bound for the United States, according to Bloomberg.
Specialized teams boarded the vessels in the Gulf of Mexico in August after indications that their networks had been compromised by foreign cyber actors, examining both operational technology and information technology systems and working with crews to remove potential threats.
One of the vessels has been identified as the VL Prosperity, a very large crude carrier capable of transporting roughly 2.3 million barrels of oil. The tanker was reportedly attacked while traveling through the Strait of Gibraltar in early August and lost communications for more than 30 hours. U.S. authorities boarded the vessel on August 21. A second tanker targeted in a separate cyberattack was boarded on August 24 for a similar assessment.
The Coast Guard and FBI said there have been no reported operational disruptions, vessel instability, physical danger to crews or environmental impacts.
John Strand, Owner, Black Hills Information Security, Inc.:
“There’s a lot of conversation right now about attacks against operational technology, especially water and power systems, given the current geopolitical climate. But tankers are absolutely on the menu as well. What makes these environments so attractive is that much of this technology doesn’t have the same endpoint security you would expect on a Windows 11 workstation. You often don’t have EDR running on these systems. That creates a rich target for attackers because many of the defensive technologies we’ve come to rely on in traditional IT simply aren’t there.”
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“It appears two separate claims are circulating, and they’re being treated as one. The first one is from the Coast Guard, which has acknowledged indications that the vessel’s network was compromised, with no reported operational disruptions. The other comes from Iranian media, citing a single unnamed crew member, which has alleged a much more extensive compromise involving cooling, fuel systems, and other critical elements of the vessel. Those claims have not been independently verified as of yet, so it’s important to keep your skeptical hat on. Additionally, it’s important to note that Iranian media reporting on the incident also does not establish Iranian responsibility; attribution remains unresolved.
“Regardless, this is a significant situation. A suspected compromise aboard a tanker warrants serious attention even if propulsion and other critical systems continued operating normally. The fact that the Coast Guard and FBI deployed their cyber teams to assess the vessel and remove potential threats shows the importance, even if it does not validate the more dramatic claims.
“The reported communications outage raises a separate technical question. A compromise of the communications suite, or plain RF interference, could explain a 30-hour outage without a threat actor ever touching the ship’s controls. GPS receivers and satellite terminals are chronically soft targets, and I spent enough of my military career working through degraded and jammed satellite comms to know how ordinary that failure mode is. The Strait of Gibraltar in particular is a well-documented GNSS interference corridor, so that’s a possibility I’d want investigators to rule in or out early, but an outage on its own still tells you nothing about how far an intrusion actually reached.
“I think if we take anything away from this ordeal, it is that nothing came of this compromise. No major disruption, environmental impact, or danger to the crew, and if a threat actor genuinely had control of propulsion on a fully loaded crude carrier, the obvious question is why nothing was done with it. When I’ve seen this pattern in the past, it usually points to a proof-of-concept or recon attack, more colloquially put, a rehearsal, not a performance. Now, a rehearsal for what? Can’t say, and neither can anyone else right now, but that’s for the investigators to work out. Either way, with global oil supply already at its tightest it’s been in modern history, this isn’t a low-consequence practice run.”
Damon Small, Board of Directors, Xcape Inc.:
“Physical maritime operations and global energy supply chains face severe operational risks when shipboard networks are compromised. Contrary to official statements downplaying the event, a 30-hour communications blackout on a crude carrier is a significant operational disruption. Vessels underway depend heavily on continuous communications for navigation and collision avoidance, meaning an unannounced blackout can easily precipitate a maritime disaster. Modern commercial watercraft rely on multi-channel connectivity including Very Small Aperture Terminal (VSAT), cellular, and Wi-Fi systems, making a sustained blackout indicative of critical bridge system failure. Defenders must strictly segment bridge communication links from physical operational technology domains, audit firmware across satellite hardware, and monitor for anomalous signal degradation.
“Critical Takeaways
“Calling a 30-hour communication blackout on a crude carrier non-disruptive is like ignoring a broken ship’s wheel because the horn still works.”
It seems like threat actors may have found a new hunting ground. That is bad news for all of us.
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 4:25 pm and is filed under Commentary with tags FBI. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.