Coast Guard, FBI Board Two Tankers After Cyberattacks
Coast Guard and FBI teams boarded two oil tankers bound for Texas after cyber intrusions disrupted navigation, engine and communications systems on at least one vessel.
US Coast Guard and FBI teams boarded two oil tankers after cyber intrusions interrupted voyages to Texas. One ship, the Liberian-flagged VL Prosperity, departed Egypt on Aug. 1 and experienced a reported intrusion on Aug. 7 while passing the Strait of Gibraltar. Crew members reported that attackers reached the engine room, reduced coolant flow, increased engine speed, disrupted fuel delivery, accessed navigation and cargo systems, and cut communications for about 30 hours.
A multiagency team of Coast Guard cyber specialists, law enforcement, a vessel inspector and members of the FBI’s Cyber Action Team boarded the VL Prosperity one day after the incident was reported and spent four days aboard. A second tanker was boarded on Aug. 24 after arriving in the Gulf of Mexico. Officials inspected the ships’ IT and operational technology and discovered evidence of a malicious cyber actor. Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, reported that nothing uncovered during the inspection ‘suggested the tanker was unsafe to operate.’
Investigators are working to determine whether the two incidents are linked and whether a nation-state actor is responsible. No public attribution to any country has been made. Quinton DuBose, a former Coast Guard cyber official, cautioned that full remote seizure of a supertanker is unlikely and described a more realistic risk as attackers degrading multiple systems enough to make safe operation difficult.
Coast Guard officials said the Prosperity boarding was among roughly 40 to 50 similar boardings by the service’s Cyber Protection Team over the past year. The activity followed the establishment of an Office of Maritime Cybersecurity Policy to centralize maritime cyber policy. Maritime cyber experts point to frequent use of aging operational technology, satellite communications and connected devices as common exposure points. Access can come through shipboard Wi‑Fi, high-frequency radio, satellite links or an infected USB drive.
Once systems are compromised, attackers can interfere with navigation, throttle and rudder controls, spoof GPS signals, alter Automatic Identification System data or disrupt cargo handling and communications. Given that about 80% of global trade moves by sea, security officials say a targeted attack on routes or ports could cause significant financial damage and supply disruptions. Investigators are analyzing forensic evidence from both ships to establish how the intrusions occurred, whether the same actors were involved and which defensive measures might prevent similar incidents.







