USCG and FBI Investigate Cyber Compromises on US-Bound Energy Tankers

🔔 Subscribe to ShipUniverse Weekly →

U.S. Coast Guard and FBI teams boarded at least two foreign-flagged energy tankers in the Gulf of Mexico in August after authorities found indications that the vessels' networks had been compromised by foreign cyber actors while they were bound for U.S. ports. The FBI said the boardings occurred on August 21 and August 24 and were intended to verify the integrity of both operational-technology and information-technology systems. One vessel has been identified in reporting as the Liberian-flagged VLCC VL Prosperity, IMO 9683697, which was carrying crude toward Galveston after departing Egypt's Sidi Kerir terminal; the second vessel carried liquefied natural gas but has not been publicly identified. U.S. authorities have not attributed the attacks to a country or group and have not confirmed Iranian media claims that hackers manipulated propulsion, navigation, engine-room or cargo systems aboard VL Prosperity. The Coast Guard said there were no reported operational disruptions, vessel instability, crew danger or environmental impacts following the response.

Maritime Cybersecurity · Energy Shipping · U.S. Investigation

Energy Tanker Cyber Investigation

Federal cyber and maritime teams boarded two U.S.-bound energy tankers after evidence indicated their networks had been compromised during voyages toward the American coast.

U.S. authorities have confirmed network compromise indicators, but have not publicly attributed the attacks or confirmed claims that propulsion, navigation or cargo-control systems were manipulated.
Affected Ships INVESTIGATION
2+
foreign energy tankers

U.S. officials say at least two vessels carrying crude oil and LNG were targeted.

Federal Boardings CONFIRMED
Aug. 21 & 24
Gulf of Mexico

Specialized Coast Guard and FBI teams boarded both ships after they reached U.S. waters.

Known Vessel IDENTIFIED
VL Prosperity
319,547-dwt VLCC

The Liberian-flagged tanker was headed toward Galveston carrying crude from Egypt.

Attribution NOT RELEASED
Unknown
foreign actors suspected

U.S. authorities have not publicly identified Iran, Russia, China or any other actor as responsible.

Confirmed Impact NO DAMAGE
None
reported operational impact

Coast Guard reporting cites no instability, injuries, crew danger or environmental effects.

Incident Sequence
Early August Gibraltar Transit U.S. officials say the tankers were targeted while transiting the Strait of Gibraltar.
August 7 VL Prosperity Claim Iranian media later claimed VL Prosperity suffered a cyberattack and lengthy communications loss. The detailed claims remain unverified by U.S. authorities.
August 21 & 24 Federal Boardings Coast Guard cyber and law-enforcement personnel, joined by FBI cyber teams, inspected the two vessels in the Gulf of Mexico.
September 15-16 Investigation Disclosed U.S. agencies publicly confirmed the cyber investigation after media inquiries and reporting on the incidents.
Confirmed Facts · Reported Claims · Open Questions

Tanker Cyberattack Evidence Board

Public reporting contains an important divide between what U.S. investigators have confirmed and more detailed technical claims that have not been independently verified.

CONFIRMED BY U.S. AUTHORITIES REPORTED BY MEDIA / VESSEL DATA TECHNICAL CLAIM NOT VERIFIED
Scroll sideways for complete evidence view ← →
Issue Status What Is Known Technical Significance What Remains Unclear Operator Relevance
Network Compromise CONFIRMED 2 Vessels Coast Guard and FBI statements say indicators showed that the networks of both vessels had been compromised. Investigators examined both information technology and operational technology rather than treating the events solely as email, communications or administrative-network breaches. Authorities have not released the initial-access method, malware family, persistence mechanism or exact systems accessed. Vessel cyber incidents can require forensic examination of systems beyond the bridge or office network when OT integrity cannot immediately be established.
Federal Response CONFIRMED USCG + FBI Specialized Coast Guard law-enforcement and Cyber Protection Team personnel boarded with FBI cyber investigators on August 21 and August 24. Coast Guard Cyber Protection Teams have incident-response, threat-hunting and forensic capabilities for Marine Transportation System networks. The agencies have not disclosed how long the forensic work continued or whether any malicious tools were recovered. U.S. cyber-incident reporting rules provide a mechanism for Coast Guard, FBI and CISA involvement when vessel systems may be compromised.
VL Prosperity IDENTIFIED IN REPORTING IMO 9683697 Bloomberg and CBS identify the Liberian-flagged 319,547-dwt VLCC as one of the investigated vessels. A VLCC of this size represents a large concentration of vessel, cargo and port-interface risk. The Coast Guard did not publicly name the tanker in its statement. Public vessel data shows the ship is approximately 333 metres long and was bound toward Galveston.
Second Tanker NAME WITHHELD LNG Cargo U.S. officials told the Wall Street Journal that the second vessel carried liquefied natural gas. LNG vessels combine navigation and propulsion dependencies with specialized cargo-containment, reliquefaction and safety systems. Vessel identity, flag, operator and exact cyber effects have not been publicly released. LNG is treated by the Coast Guard as an especially hazardous cargo requiring elevated security planning.
Engine-System Manipulation UNVERIFIED CLAIM Iranian Media Iranian reporting alleged that attackers affected engine cooling, engine speed, fuel and lubricating-oil systems aboard VL Prosperity. If independently verified, manipulation of those systems would represent OT interference rather than a conventional business-network intrusion. U.S. investigators have not confirmed that these machinery effects occurred. The distinction between an IT compromise and demonstrated control of safety-critical machinery is central to evaluating incident severity.
30-Hour Communications Loss UNVERIFIED CLAIM 30 Hours Iranian state media reported that VL Prosperity lost communications for approximately 30 hours following the alleged August 7 attack. Extended loss of external communications can complicate reporting, coordination, fleet support and cyber containment. Neither the Coast Guard nor FBI has publicly validated the claimed duration or cause of the communications outage. Communications loss alone does not establish that propulsion, navigation or cargo systems were compromised.
Physical Consequences NONE REPORTED No Casualty Coast Guard reporting says there were no operational disruptions, vessel instability, injuries, crew danger or environmental impacts. The investigation therefore centers on cyber integrity rather than response to a collision, grounding, fire or spill. Authorities have not said whether safeguards or crew intervention prevented a larger consequence. Demonstrated network compromise without a casualty still requires operators to establish that critical systems are trustworthy before normal operation.
Attribution OPEN No Actor Named Officials describe the compromises as involving foreign cyber actors. Attribution typically requires infrastructure, malware, intelligence and operational evidence beyond the presence of a compromise. U.S. authorities have not publicly assigned responsibility to Iran or any other government or organization. Iranian media coverage of an incident is not evidence that Iran conducted the intrusion.
Scroll sideways from either bar ← →
Maritime Cyber Context
2025 MTS Incidents 43%
Share of reported Marine Transportation System cyber incidents in which phishing was used for reconnaissance or initial access, according to CGCYBER.
2024 Comparison 25%
Comparable phishing figure from the previous year.
Cyber Rule Jul. 2025
Coast Guard baseline Marine Transportation System cybersecurity rule became effective July 16, 2025.
Incident Reporting USCG · FBI · CISA
Federal reporting framework provides for notification when actual or threatened maritime cyber incidents are detected.
Ship Universe Cyber Incident Tool

Tanker Cyber Delay & Cost Exposure Analyzer

Model the commercial exposure created when a vessel is held for cyber investigation, forensic verification, system restoration or delayed port clearance.

hours
The 30-hour default mirrors the unverified communications-loss duration reported for VL Prosperity. Change it to model other incidents.
$/day
Editable planning assumption, not a published VL Prosperity charter rate.
bbl
Approximately 2 million barrels was reported for the VL Prosperity voyage.
$/bbl
User-entered value for measuring cargo capital tied up during delay.
% / yr
$
Illustrative incident-response assumption.
Modeled Direct Exposure $245K vessel delay + cargo carry + entered cyber-response expense
Delay Duration 1.25 d entered incident hours converted to days
Vessel-Time Cost $94K modeled vessel rate multiplied by delay
Cargo Capital at Risk $200M cargo quantity multiplied by entered commodity value
Cargo Carry Cost $55K financing cost associated with delayed cargo capital
Exposure per Incident Hour $8.2K modeled direct exposure divided by incident duration
Modeled Cost Stack
This separates ordinary vessel-delay cost from cargo financing and direct cyber-response expense.
Vessel Delay
$94K
Cargo Carry
$55K
Cyber Response
$150K
Cargo / Vessel Scale $200M
Nominal cargo value represented by the entered barrel quantity and oil-price assumption. This is not a loss estimate. It shows the scale of cargo capital tied to the voyage while cyber integrity is being established.
Cargo 2.0M bbl
Delay 30 h
Daily Rate $75K
Carry Rate 8.0%
Scenario model: This calculator does not estimate cyberattack probability, liability, ransom, casualty losses, spill exposure or insurance recovery. Vessel rate, commodity price, financing rate and response expense are editable assumptions. The reported 30-hour communications loss involving VL Prosperity has not been confirmed by U.S. authorities and is used only as a selectable scenario benchmark.
Feedback Welcome

We welcome your feedback, suggestions, corrections, and ideas for enhancements.

Please click here to get in touch
By the ShipUniverse Editorial Team — About Us | Contact