Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
US Coast Guard and FBI boarded two oil tankers after cyberattacks disrupted engines, navigation, and communications; suspected Iranian involvement remains unconfirmed.
Two tankers bound for Texas, including the Liberian-flagged VL Prosperity, were boarded by Coast Guard and FBI Cyber Action Team personnel after cyberattacks during their voyages. An August 7 intrusion allegedly reached the engine room, slowing coolant flow, raising engine speed, interfering with fuel delivery, and cutting communications for about 30 hours. Investigators confirmed evidence of a malicious cyber actor but have not attributed the attacks, with Iranian state involvement suspected but unverified. The Coast Guard has conducted 40-50 similar boardings in the past year and recently established an Office of Maritime Cybersecurity Policy.
- Attack on VL Prosperity reportedly occurred August 7 near the Strait of Gibraltar, per Iranian media
- Hackers reached the engine room, altering coolant flow, engine speed, and fuel delivery
- Ship communications were cut for roughly 30 hours; navigation and cargo systems were accessed
- Coast Guard confirmed a malicious cyber actor was present; attribution to Iran unconfirmed
- Boarding was one of 40-50 cyber inspections by the Coast Guard in the past year
Full article589 words · extracted from securityweek.com · click to collapse
Two oil tankers bound for Texas were boarded by US Coast Guard and FBI personnel last month after cyberattacks disrupted the vessels during their voyage toward the United States, according to a CBS News report citing US officials.
One of the ships, the VL Prosperity, is a Liberian-flagged crude tanker that left Egypt on August 1 en route to Galveston, Texas, per vessel-tracking records cited by CBS News.
Iran’s Mehr News Agency reported on August 20 that the cyberattack had allegedly occurred on August 7 as the tanker passed through the Strait of Gibraltar. Citing a crew member, the Iranian outlet said the intrusion reached the engine room, with hackers slowing coolant flow, raising engine speed and interfering with fuel delivery.
Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference
The hackers also allegedly accessed navigation and cargo systems and cut off the ship’s communications for roughly 30 hours.
One day after Mehr’s report, a team that included Coast Guard cyber specialists, law enforcement, a vessel inspector, and FBI Cyber Action Team members boarded the VL Prosperity and spent four days aboard.
Advertisement. Scroll to continue reading.
The Wall Street Journal reported that the second ship was boarded on August 24. Both vessels were boarded after they arrived in the Gulf of Mexico.
The Coast Guard has not publicly linked the incident to Iran. Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, told CBS News that investigators did find evidence of a malicious cyber actor after reviewing the vessel’s IT and other onboard systems.
She noted that nothing uncovered during the inspection suggested the tanker was unsafe to operate. This was one of an estimated 40-50 similar boardings the Coast Guard’s Cyber Protection Team has carried out over the past year, Grable said.
Quinton DuBose, a former Coast Guard cyber official, pushed back on the idea that hackers could seize full command of a supertanker, arguing the more realistic risk is an attacker degrading enough individual systems to make safe operation difficult.
Investigators are still working to determine whether the two tanker incidents are connected and whether Iran or another state actor is responsible. DuBose urged caution around the Iranian coverage, noting that Iran-linked actors have a history of overstating their cyber capabilities.
Cyber threats to the maritime sector
The incident comes just days after the US Coast Guard announced a dedicated Office of Maritime Cybersecurity Policy, which will serve as its central authority for developing and implementing policies governing the cyber safety and security of the marine transportation system.
The cybersecurity community has long warned that the maritime sector’s reliance on aging, unmanaged OT systems, satellite communications, and connected IoT devices leaves both vessels and ports dangerously exposed to cyberattack.
Attackers can exploit WiFi, HF radio, and SATCOM links — or simply an infected USB stick — to gain access, with successful compromise potentially granting remote control over a ship’s throttle, rudder, or navigation systems.
Beyond ransomware, which has already disrupted shipping operations, experts point to even more severe scenarios such as GPS spoofing, AIS manipulation to disguise a vessel’s true location, or deliberately running a ship aground to block a critical waterway.
Given that roughly 80% of global goods move by sea, a targeted attack could trigger billions of dollars in losses and cascading supply shortages.
Related: Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Related: US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
Related: White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/cyberattacks-on-two-oil-tankers-prompt-coast-guard-fbi-to-board-vessels/