U.S. federal authorities, including the Coast Guard and FBI, boarded two Texas-bound energy tankers last month following cyberattacks that targeted the vessels as they made their way toward the United States. The joint operations highlight growing anxieties over the vulnerability of maritime critical infrastructure to remote digital disruption.
One of the targeted ships has been identified as the VL Prosperity, a massive 1,093-foot crude oil tanker flying a Liberian flag and destined for Galveston, Texas. This supertanker, spanning the length of more than three football fields, is capable of transporting approximately 2.3 million barrels of crude oil. Public shipping data shows the vessel began its journey from Egypt's Sidi Kerir oil terminal on August 1. It reportedly experienced a slowdown near the Strait of Gibraltar around the time the cyberattack occurred, before continuing its voyage across the Atlantic Ocean toward American shores.
A second energy tanker heading to Texas was also targeted by a cyberattack. U.S. investigators are currently looking into whether the two incidents are connected and whether a foreign adversary, such as Iran, was the perpetrator behind the operations.
Iranian state media was quick to identify the VL Prosperity shortly after the incident occurred. The state-run outlets claimed that hackers had successfully infiltrated the supertanker's navigation, propulsion, and cargo systems, completely disabling its communications for a period of 30 hours. Specifically, Iran's Mehr News Agency reported on August 20 that the VL Prosperity was targeted on August 7 during its transit through the Strait of Gibraltar. Citing an unnamed crew member, the agency alleged that hackers breached the ship's engine room, manipulated fuel systems, increased engine speed, and reduced the flow of engine cooling systems.
On August 21, the day after the Iranian report, a team comprising Coast Guard cyber personnel, law enforcement officers, a vessel inspector, and operators from the FBI's Cyber Action Team boarded the VL Prosperity. The joint team remained on the vessel for four days. Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, explained in an interview that interagency partners had alerted Coast Guard teams, who then went offshore alongside the FBI to climb aboard the tanker. This operation represents one of approximately 40 to 50 offshore missions conducted by the Coast Guard's Cyber Protection Team over the past year.
According to Grable, the investigators' primary objective was to hunt for malware and analyze information technology systems to eliminate any malicious activity. She confirmed that while the Coast Guard has not publicly blamed Iran for the attacks, investigators did uncover concrete evidence of a malicious cyber actor. "They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity," Grable stated. Importantly, she emphasized that the boarding teams did not find any evidence suggesting the ship had become unsafe to navigate at the time they boarded. The Coast Guard intends to analyze the gathered data and provide the vessel's owner with recommendations to patch identified vulnerabilities.
The incident highlights a growing vulnerability as modern commercial ships become increasingly reliant on internet-connected systems for navigation, propulsion, steering, ballast, and other critical machinery. Grable expressed deep concern over the integration of these systems. "The real thing we're concerned about is those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel," she said. She warned that highly connected vessels are highly susceptible to cyber threats, which could result in "a vessel blocking a waterway or a pollution incident or any other number of safety and security hazards to our ports and waterways."
The prospect of a compromised supertanker near a major U.S. port is a primary concern for maritime authorities. Grable noted, "Of course we're worried about a collision, an explosion, anything that blocks the channel for other vessels to safely enter and exit the port, pollution incidents — we're kind of worried about the whole gamut." The potential economic fallout is massive, given that $5.4 trillion in commerce flows through U.S. ports each year. Even minor delays can trigger significant disruptions. "Any small delay, because of a cyber breach, like, for example, if a port has to shift to manual operations, it causes a big delay with tankers and cargo vessels coming in and out of the port," Grable explained.
Grable warned that the technical barrier for such attacks is surprisingly low. When asked about the level of sophistication required to move from hacking a computer network to manipulating physical ship machinery, she replied, "Not necessarily that sophisticated. There is malicious source code that people can get their hands on." She added that this code is readily available and noted that "artificial intelligence is accelerating the rate at which we need to take action." To counter this, she urged operators to implement basic cyber hygiene, network segmentation, and defenses against phishing attacks, stating that "just taking basic precautions would prevent most of these occurrences."
Cybersecurity experts agree that the risk is real. Rob Lee, the CEO of industrial cybersecurity firm Dragos, which specializes in operational technology, commented on the technical plausibility of the Iranian claims. "The details that they published, from what we understand of these types of vehicles and ships and similar, is spot on," Lee said. "Everything they're saying is very realistic." Lee explained that on many ships, a single firewall is the only barrier separating a satellite internet connection from critical onboard systems, which often share a single network containing navigation, propulsion, ballast, steering, and ship command systems. He warned that artificial intelligence could exacerbate this vulnerability by helping attackers identify weakly protected, internet-facing systems on energy carriers. "The very thing that we think is our one protection — not that you should have one protection — is the very thing that AI is actually really good at," Lee remarked.
When asked if cyber access to a vessel could lead to a form of remote hijacking, Grable agreed it was a fair characterization of the broader risk. Lee also deemed the scenario realistic, noting that an attacker could remotely manipulate a maritime asset and potentially run it aground. However, Quinton DuBose, a former Coast Guard cyber official, offered a more cautious perspective. "I'd be kind of cautious about saying that somebody can just take control of the ship," DuBose said, pointing out that "ships are incredibly complicated systems." Instead, DuBose suggested that the more realistic threat is the disruption of critical subsystems. "Rather than looking at it as, 'okay, I'm going to take full control of this thing,' it's, 'what systems can I disrupt to the point where it affects the safe handling and makes the ship less safe to operate,'" he explained.
While Iranian state media heavily publicized the incident, U.S. authorities have remained cautious about official attribution. Four days after Mehr's initial report, Iran's Tasnim News Agency ran an article titled "No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?" DuBose cautioned that the Iranian narrative is unverified, noting that Iranian-linked actors frequently exaggerate their cyber capabilities. He added that cyber attribution is a complex process that can take weeks or months. Grable explained that investigators analyze "tactics, techniques and protocols that certain adversaries use — kind of like their trademark fingerprints on how they gain access to systems and what they do and what their payloads are" (referred to as TTPs) to identify the culprits.
As commercial vessels increasingly adopt satellite communications and link their IT networks with onboard control systems, the entry points for cybercriminals become more porous. DuBose emphasized that the maritime industry must take these threats seriously, noting that the federal government "has increasingly imposed baseline cyber requirements across the sector." Grable concluded with a direct warning to vessel owners and operators: "We need everybody to pay attention to this."
Related Articles

Md. Kazi Bijoy is a dedicated tech enthusiast and content creator with a passion for digital innovation. With years of experience in the tech industry, he specializes in breaking down complex topics into easy-to-understand guides. When he isn’t writing, he explores the latest gadgets and researches emerging trends in the digital world.
