FBI and Coast Guard Board Hacked Oil Tankers in Gulf of Mexico

Agencies investigate suspected Iranian involvement after navigation and propulsion systems compromised

By LineZotpaper
Published
Read Time2 min
Cybersecurity teams from the FBI and U.S. Coast Guard boarded two U.S.-bound oil tankers in the Gulf of Mexico last month after hackers reportedly seized control of navigation, propulsion, and cargo systems on at least one vessel, raising concerns about maritime cyberattacks amid heightened tensions with Iran.

According to a joint statement shared with TechCrunch, the agencies boarded the vessels between August 21 and August 24 to “ensure integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised.” The Coast Guard released photos of FBI agents and staff climbing aboard one of the tankers.

The statement said the captain, crew, and onshore staff of the vessel’s owner cooperated with the boarding and that there were “no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”

CBS News identified one of the tankers as the VL Prosperity, a 333-meter oil tanker capable of holding over 2 million barrels of oil, currently located in the Gulf of Mexico. Citing Iranian media, CBS reported that hackers compromised the ship on August 7 while it was traveling from Egypt to the United States, interfering with its speed and fuel systems and causing a loss of communications for more than a day.

The U.S. is investigating whether Iran is behind the attack, according to CBS. Iranian-backed hackers have launched multiple cyberattacks in recent months following the U.S. and Israel-led war against Tehran, including a destructive hack at medical device maker Stryker, a breach of the Los Angeles transit system, and compromises of over a hundred U.S. water facilities. The Cybersecurity and Infrastructure Security Agency has described the attacks as “opportunistic."

§

Analysis

Why This Matters

  • The incident highlights the vulnerability of critical maritime infrastructure to sophisticated cyberattacks that could cause environmental disasters or disrupt global supply chains.
  • With tensions high after the U.S.-led bombing of Iran, the attack suggests that hackers are targeting industrial control systems on commercial vessels, not just corporate networks.
  • The boarding operation underscores the need for improved cybersecurity standards across the shipping industry, particularly for vessels transiting geopolitically sensitive routes.

Background

Maritime shipping networks are complex, with integrated systems for navigation, propulsion, cargo management, and communications. Tankers like the VL Prosperity carry millions of barrels of oil, making them high-value targets. The U.S. has warned for years about the risk of cyberattacks on ships, but actual incidents involving full compromise of operational technology systems remain rare. This event comes amid a broader campaign by Iranian-backed hackers targeting critical U.S. infrastructure since February, following the death of Iran's supreme leader in a U.S.-Israel military operation.

Key Perspectives

U.S. government: The FBI and Coast Guard are investigating the compromise and assessing whether Iran is responsible, but have not publicly attributed the attack. The joint statement emphasized that no physical harm or environmental damage occurred. Shipping industry: The incident will likely accelerate calls for better cybersecurity measures on vessels, including network segmentation, crew training, and incident response plans. The industry faces challenges in securing aging systems connected to the internet. Critics/Skeptics: Attribution in maritime cyberattacks is difficult, and no group has claimed responsibility. Some analysts caution that other threat actors could exploit similar techniques, and that the U.S. response could escalate tensions further.

What to Watch

  • Official attribution by the U.S. government, potentially linking the hack to Iran or other state-sponsored groups.
  • Additional maritime cyber incidents as hackers probe vulnerabilities in the wake of this attack.
  • Implementation of new Coast Guard guidelines for vessel cybersecurity or international maritime security protocols.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.