USCG and FBI Investigate Cyber Compromises on US-Bound Energy Tankers

🔔 Subscribe to ShipUniverse Weekly →
U.S. Coast Guard and FBI teams boarded at least two foreign-flagged energy tankers in the Gulf of Mexico in August after authorities found indications that the vessels' networks had been compromised by foreign cyber actors while they were bound for U.S. ports. The FBI said the boardings occurred on August 21 and August 24 and were intended to verify the integrity of both operational-technology and information-technology systems. One vessel has been identified in reporting as the Liberian-flagged VLCC VL Prosperity, IMO 9683697, which was carrying crude toward Galveston after departing Egypt's Sidi Kerir terminal; the second vessel carried liquefied natural gas but has not been publicly identified. U.S. authorities have not attributed the attacks to a country or group and have not confirmed Iranian media claims that hackers manipulated propulsion, navigation, engine-room or cargo systems aboard VL Prosperity. The Coast Guard said there were no reported operational disruptions, vessel instability, crew danger or environmental impacts following the response.
Energy Tanker Cyber Investigation
Federal cyber and maritime teams boarded two U.S.-bound energy tankers after evidence indicated their networks had been compromised during voyages toward the American coast.
U.S. officials say at least two vessels carrying crude oil and LNG were targeted.
Specialized Coast Guard and FBI teams boarded both ships after they reached U.S. waters.
The Liberian-flagged tanker was headed toward Galveston carrying crude from Egypt.
U.S. authorities have not publicly identified Iran, Russia, China or any other actor as responsible.
Coast Guard reporting cites no instability, injuries, crew danger or environmental effects.
Tanker Cyberattack Evidence Board
Public reporting contains an important divide between what U.S. investigators have confirmed and more detailed technical claims that have not been independently verified.
| Issue | Status | What Is Known | Technical Significance | What Remains Unclear | Operator Relevance |
|---|---|---|---|---|---|
| Network Compromise | CONFIRMED 2 Vessels | Coast Guard and FBI statements say indicators showed that the networks of both vessels had been compromised. | Investigators examined both information technology and operational technology rather than treating the events solely as email, communications or administrative-network breaches. | Authorities have not released the initial-access method, malware family, persistence mechanism or exact systems accessed. | Vessel cyber incidents can require forensic examination of systems beyond the bridge or office network when OT integrity cannot immediately be established. |
| Federal Response | CONFIRMED USCG + FBI | Specialized Coast Guard law-enforcement and Cyber Protection Team personnel boarded with FBI cyber investigators on August 21 and August 24. | Coast Guard Cyber Protection Teams have incident-response, threat-hunting and forensic capabilities for Marine Transportation System networks. | The agencies have not disclosed how long the forensic work continued or whether any malicious tools were recovered. | U.S. cyber-incident reporting rules provide a mechanism for Coast Guard, FBI and CISA involvement when vessel systems may be compromised. |
| VL Prosperity | IDENTIFIED IN REPORTING IMO 9683697 | Bloomberg and CBS identify the Liberian-flagged 319,547-dwt VLCC as one of the investigated vessels. | A VLCC of this size represents a large concentration of vessel, cargo and port-interface risk. | The Coast Guard did not publicly name the tanker in its statement. | Public vessel data shows the ship is approximately 333 metres long and was bound toward Galveston. |
| Second Tanker | NAME WITHHELD LNG Cargo | U.S. officials told the Wall Street Journal that the second vessel carried liquefied natural gas. | LNG vessels combine navigation and propulsion dependencies with specialized cargo-containment, reliquefaction and safety systems. | Vessel identity, flag, operator and exact cyber effects have not been publicly released. | LNG is treated by the Coast Guard as an especially hazardous cargo requiring elevated security planning. |
| Engine-System Manipulation | UNVERIFIED CLAIM Iranian Media | Iranian reporting alleged that attackers affected engine cooling, engine speed, fuel and lubricating-oil systems aboard VL Prosperity. | If independently verified, manipulation of those systems would represent OT interference rather than a conventional business-network intrusion. | U.S. investigators have not confirmed that these machinery effects occurred. | The distinction between an IT compromise and demonstrated control of safety-critical machinery is central to evaluating incident severity. |
| 30-Hour Communications Loss | UNVERIFIED CLAIM 30 Hours | Iranian state media reported that VL Prosperity lost communications for approximately 30 hours following the alleged August 7 attack. | Extended loss of external communications can complicate reporting, coordination, fleet support and cyber containment. | Neither the Coast Guard nor FBI has publicly validated the claimed duration or cause of the communications outage. | Communications loss alone does not establish that propulsion, navigation or cargo systems were compromised. |
| Physical Consequences | NONE REPORTED No Casualty | Coast Guard reporting says there were no operational disruptions, vessel instability, injuries, crew danger or environmental impacts. | The investigation therefore centers on cyber integrity rather than response to a collision, grounding, fire or spill. | Authorities have not said whether safeguards or crew intervention prevented a larger consequence. | Demonstrated network compromise without a casualty still requires operators to establish that critical systems are trustworthy before normal operation. |
| Attribution | OPEN No Actor Named | Officials describe the compromises as involving foreign cyber actors. | Attribution typically requires infrastructure, malware, intelligence and operational evidence beyond the presence of a compromise. | U.S. authorities have not publicly assigned responsibility to Iran or any other government or organization. | Iranian media coverage of an incident is not evidence that Iran conducted the intrusion. |
Tanker Cyber Delay & Cost Exposure Analyzer
Model the commercial exposure created when a vessel is held for cyber investigation, forensic verification, system restoration or delayed port clearance.
We welcome your feedback, suggestions, corrections, and ideas for enhancements.
Please click here to get in touch