Hackers breached propulsion system of U.S.-bound oil supertanker

The FBI and The U.S.Coast Guard investigators found evidence that hackers gained access to the digital propulsion system of the VL Prosperity, a fully loaded oil supertanker bound for Galveston, Texas, according to Bloomberg.

The hackers had temporary access to the propulsion system as the vessel approached the Texas coast this summer. Investigators have not determined how the attackers gained access, how long they remained in the system, who was responsible or what ship functions they may have been capable of controlling.

The FBI and Coast Guard boarded the VL Prosperity in August after the vessel lost communications and authorities received indications that its network had been compromised. The agencies also boarded a second vessel in the Gulf of Mexico because of a suspected cyber threat. By September, U.S. agencies were tracking cyber threats involving nearly 20 vessels around the world and had requested advance notice if any planned to enter a U.S. port. The VL Prosperity remains anchored offshore Galveston as the investigation continues.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Access and control are separate findings, and the public evidence on VL Prosperity stops before engine control. If investigators can show that an intruder reached a write-capable propulsion controller and issued a valid command, this would be the first publicly documented, independently confirmed cyberattack against a commercial vessel’s propulsion controls. That is a much bigger claim than temporary access to a digital system.

“Bloomberg reports that investigators found temporary access to the tanker’s digital propulsion system. The public joint statement from the Federal Bureau of Investigation and U.S. Coast Guard says the agencies boarded the vessel to examine its information technology (IT) and operational technology (OT) systems after indications that its networks were compromised. It reports no operational disruption, vessel instability, physical danger to the crew, or environmental impact.

“That distinction matters because a propulsion-related bridge console, engineering workstation, machinery automation gateway, and engine controller are materially different findings. The U.S. Coast Guard’s 2019 response to a malware incident aboard a deep-draft vessel is the useful comparison. The malware seriously degraded the ship’s onboard computer network, but investigators found that essential vessel control systems were unaffected. Maersk made a similar distinction during the 2017 NotPetya attack, when its shore and terminal systems were disrupted while its vessels remained maneuverable.

“The closest publicly documented physical-control event was the 2013 University of Texas test that moved a yacht off course by spoofing the Global Positioning System (GPS) and inducing navigation corrections. The researchers did not control the engine. In 2025, French authorities investigated Remote Access Trojan (RAT) malware found on the Fantastic ferry, but the operator said the intrusion was neutralized without operational consequences.

“VL Prosperity could change that record. The decisive evidence is a forensic trail showing a write-capable session sent a valid command to the engine controller and that the controller accepted it. Until authorities produce that, call this a propulsion-access incident. The public record does not yet support a confirmed propulsion takeover.”

ㅤ

Damon Small, Board of Directors, Xcape, Inc.:

“The rapid escalation from a single novel maritime intrusion to federal tracking of nearly 20 compromised vessels globally directly threatens an already precarious global oil market, creating upward pressure on crude prices and downstream refined products. These supertankers operate as self-sufficient floating cities governed by complex operational technology (OT) systems that manage crew life support, navigation, and critical cargo onboarding and offboarding. Although threat actor attribution remains unconfirmed, the scale and sophistication strongly suggest coordinated state-sponsored activity targeting maritime OT.

“A widespread compromise across vessel networks could ground entire fleets or trigger catastrophic physical disruption at sea. To mitigate these systemic risks, asset owners must enforce rigorous physical and digital network segmentation between vessel bridge controls, satellite communications, and IT networks, while implementing unidirectional security gateways and mandatory anomaly monitoring across onboard industrial control systems.”

“Critical Takeaways

  • “Escalating Market Impact: Global tracking of nearly 20 compromised vessels shifts maritime cyber risk from an isolated novelty to a material supply chain threat capable of driving up global oil prices.
  • “Complex OT Vulnerabilities: Supertankers rely on interconnected OT for life support, propulsion, and cargo operations, making unauthorized access to onboard control networks potentially devastating to fleet operations.
  • “Essential Defensive Controls: Security teams must enforce strict network segmentation between bridge IT, satellite communications, and OT systems, backed by unidirectional gateways and continuous industrial network monitoring.

“Air-gapping vessel networks only works if you do not run an ethernet cable straight from the satellite dish to the propulsion engine.”

Ladies and gentlemen, we welcome you to your next high value target. The good thing is that many of the defensive strategies are pretty much the same. Therefore those should be employed ASAP.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading