FBI and Coast Guard Board Oil Tankers After Cyberattacks Disrupted Vessels Mid-Voyage
Two oil tankers heading for Texas were boarded by US Coast Guard and FBI personnel last month following cyberattacks that hit the ships during their transatlantic passages. The story, first reported by CBS News citing US officials, offers a rare public glimpse into what the Coast Guard says is a surprisingly routine occurrence.
One of the vessels, the VL Prosperity, is a Liberian-flagged crude tanker that departed Egypt on 1 August, bound for Galveston. According to Iran's Mehr News Agency, the attack happened on 7 August as the ship transited the Strait of Gibraltar. A crew member cited by the outlet claimed hackers got into the engine room, messing with coolant flow, ramping up engine speed, and interfering with fuel delivery. Navigation and cargo systems were also reportedly accessed, and the ship's communications were cut for around 30 hours.
A day after that report surfaced, a boarding team made up of Coast Guard cyber specialists, law enforcement officers, a vessel inspector, and FBI Cyber Action Team members went aboard the VL Prosperity and stayed for four days. A second vessel was boarded on 24 August, per the Wall Street Journal. Both ships were inspected after reaching the Gulf of Mexico.
The Coast Guard has stopped well short of publicly blaming Iran. Rear Admiral Amy Grable, commander of Coast Guard Cyber Command, confirmed to CBS News that investigators did find evidence of a malicious actor after combing through the ship's IT and onboard systems, but stressed nothing found indicated the tanker was unsafe to sail. She also revealed this was just one of an estimated 40 to 50 similar boardings the Coast Guard's Cyber Protection Team has conducted over the past year. That number alone should give pause.
Former Coast Guard cyber official Quinton DuBose poured cold water on the more dramatic version of events, arguing that a hacker seizing full command of a supertanker is not a realistic threat model. The more plausible scenario, he said, is an attacker quietly degrading enough individual systems to make safe operation genuinely difficult. He also urged scepticism about the Iranian reporting, noting that Iran-linked actors have a well-documented habit of overstating what they have actually done.
Investigators are still working out whether the two incidents are connected and who is behind them.
The timing is notable. Just days before the boardings became public, the Coast Guard announced a new dedicated Office of Maritime Cybersecurity Policy, intended to centralise how it develops and enforces cyber safety rules across the marine transport network.
The vulnerabilities in maritime systems are not new, and the security community has been banging this drum for years. Ships routinely rely on aging operational technology that was never designed to be networked, combined with satellite comms, connected IoT sensors, and crew members occasionally plugging in infected USB sticks. Any of those entry points can hand an attacker a foothold, and from there the potential consequences range from ransomware locking up shore-side operations to GPS spoofing, manipulation of AIS tracking data, or in the most severe scenarios, deliberately grounding a vessel to block a critical shipping lane.
With roughly 80 percent of global goods moving by sea, the economic blast radius from a well-executed attack on maritime infrastructure would be enormous. The VL Prosperity incident may or may not turn out to be a significant escalation. Either way, it is a useful reminder that cyber threats to shipping are no longer theoretical.