FBI and Coast Guard Investigate Cyberattacks on U.S.-Bound Energy Tankers

The FBI and Coast Guard are investigating cyberattacks against 2 U.S.-bound energy tankers after evidence emerged that their networks were compromised.
Oil tanker sailing through dark ocean waters at night with glowing red cyberattack indicators highlighting critical systems across the vessel.

The FBI and U.S. Coast Guard are investigating suspected cyberattacks against 2 foreign-flagged energy tankers bound for the United States after indications that the vessels’ networks had been compromised by foreign cyber actors.

Federal cyber specialists boarded the vessels in the Gulf of Mexico on Aug. 21 and Aug. 24 to assess their information technology and operational technology environments and determine whether the compromises posed a threat to the ships, their crews or U.S. port infrastructure.

One of the vessels has been identified in public reporting as the VL Prosperity, a Liberian-flagged crude oil supertanker capable of carrying roughly 2.3 million barrels. The second vessel has been described as another energy tanker.

U.S. authorities said there were no reports of operational disruptions, vessel instability, physical danger to crew members or environmental impacts following the incidents.

Federal cyber teams boarded both vessels

The first response occurred Aug. 21, when a specialized team of Coast Guard law enforcement officers, cyber protection personnel and FBI cyber specialists boarded a foreign-flagged commercial vessel in the Gulf of Mexico.

According to a joint statement from the agencies, the boarding was intended to ensure the integrity of the vessel’s operational and information technology systems after authorities received indications that its network had been compromised by foreign cyber actors.

A second foreign-flagged vessel was boarded on Aug. 24 after authorities received similar indications of a network compromise.

Investigators assessed both conventional IT infrastructure and systems associated with vessel operations, an important distinction because modern commercial ships increasingly rely on interconnected digital systems for navigation, propulsion, steering, communications, ballast management and other functions.

The crews cooperated with investigators, and federal authorities said they were communicating with vessel owners, port operators and other maritime stakeholders to ensure port operations continued safely.

VL Prosperity reportedly lost communications for 30 hours

Public reporting has identified one of the vessels as the VL Prosperity, a supertanker that was transporting crude oil from Egypt toward the U.S. Gulf Coast.

The vessel reportedly experienced a suspected cyberattack while transiting near the Strait of Gibraltar in August and lost communications for approximately 30 hours.

Iranian state media subsequently claimed attackers had interfered with systems aboard the vessel, including equipment associated with the engine room, propulsion and other ship functions.

Those specific claims have not been confirmed by the FBI or Coast Guard.

U.S. investigators have confirmed finding evidence of malicious cyber activity associated with the vessel, but authorities have not publicly disclosed whether attackers successfully manipulated its propulsion, navigation or cargo systems.

The VL Prosperity ultimately continued toward the United States and arrived near the Texas coast. Its technical manager said the vessel was cleared for normal operations following the Coast Guard assessment.

Operational technology raises stakes of maritime attacks

The investigations highlight the potential consequences of cyberattacks against modern commercial vessels, where compromises can extend beyond stolen information or disabled communications.

Large tankers rely on digital technology to support critical shipboard functions. If an attacker moves from an internet-connected IT environment into operational technology, a compromise could potentially affect navigation, propulsion, steering, cargo handling or other machinery required to safely operate the vessel.

Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, said investigators are particularly concerned about connections between traditional IT systems and equipment controlling critical vessel functions.

A successful attack affecting those systems could potentially contribute to a collision, pollution event, blocked shipping channel or other maritime safety incident.

Neither of the 2 incidents under investigation resulted in those consequences, according to U.S. authorities.

The Coast Guard said there were no reports of vessel instability, danger to crew members or environmental impacts, and port operations continued without interruption.

U.S. has not attributed the cyberattacks

No threat actor has been publicly identified as responsible for either incident.

U.S. investigators are examining whether the attacks are connected and whether a foreign government or state-linked operation may have been involved.

Iran has emerged as one line of inquiry in public reporting, particularly because Iranian state media published detailed claims about the VL Prosperity incident before U.S. authorities publicly disclosed their investigation.

That timing does not establish Iranian responsibility. Neither the FBI nor Coast Guard has attributed the attacks to Iran or any other country, and no verified evidence publicly establishes who conducted the intrusions.

Investigators can use malware, infrastructure and attacker tactics, techniques and procedures to compare activity against previously identified cyber operations, but reliable attribution can take significant time.

Connected ships expand maritime attack surface

The investigations come as commercial shipping becomes increasingly dependent on connected systems and satellite communications.

Digital platforms allow vessel operators to monitor machinery, optimize routes, reduce fuel consumption and remotely exchange operational information. Those connections can also create additional pathways for attackers if networks are poorly segmented or internet-facing systems contain exploitable vulnerabilities.

The Coast Guard has increasingly emphasized cybersecurity across the U.S. maritime transportation system as ships, ports and cargo operations become more digitally interconnected.

Even an attack that does not directly manipulate a vessel could have significant consequences if operators are forced to disconnect systems, switch to manual procedures or delay port movements while investigating a compromise.

The FBI and Coast Guard investigations into both tankers remain active. Authorities have not publicly disclosed the initial access method, malware involved or technical indicators associated with the attacks.

For now, federal authorities say both incidents were contained without reported operational disruption or environmental damage, while investigators continue working to determine who targeted the vessels and whether the 2 attacks are connected.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site