threat_intelligence876 wordsRead on Arc Codex

Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk

U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they were underway, according to U.S. officials. One of the ships was the VL Prosperity, a 1,093‑foot Liberian‑flagged crude oil supertanker headed to Galveston, Texas. Iranian state media identified the ship soon after the incident and claimed hackers gained access to propulsion, navigation and cargo systems, knocking out communications for about 30 hours. “U.S. Coast Guard personnel and FBI agents boarded two Texas-bound energy tankers last month after cyberattacks struck the vessels while they were traveling toward the United States, according to U.S. officials.” CBS News reports. The Coast Guard has not publicly pinned the attacks on Iran. Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, told CBS News that investigators did find evidence of a malicious cyber actor after assessing the vessel’s IT and other onboard systems. “They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity,” Grable told CBS News. “When these vessels are highly connected, they’re susceptible to cyber threats,” Grable said, warning that an attack could lead to “a vessel blocking a waterway or a pollution incident or any other number of safety and security hazards to our ports and waterways.” The U.S. is still working to determine whether the two cyberattacks are connected and whether Iran or another foreign adversary was behind them. The VL Prosperity, a supertanker carrying about 2.3 million barrels of oil, reportedly suffered a cyberattack on Aug. 7 near the Strait of Gibraltar. The vessel had left Egypt for Galveston and slowed near Gibraltar around the time of the incident. An Iranian report, citing an unnamed crew member, claimed hackers breached the engine room and interfered with cooling, engine speed and fuel systems. Grable said Coast Guard teams had been alerted by interagency partners and went offshore with the FBI to climb aboard, one of roughly 40 to 50 missions the Coast Guard’s Cyber Protection Team has undertaken in the past year. Investigators hunted for malware and combed through IT systems to root out malicious activity, with a particular focus on whether those IT systems were connected to propulsion, navigation and other critical safety systems. Response teams did not find any evidence indicating the ship had become unsafe to navigate when they boarded it. The concern around large cargo vessels and maritime critical infrastructure goes well beyond stolen files or disrupted communications. Modern commercial vessels increasingly run on internet‑connected systems for navigation, propulsion, steering, ballast and other critical machinery, so a cyberattack that penetrates those operational systems could be weaponized or manipulated. Authorities fear the danger of a large vessel being compromised near an American port. “Of course we’re worried about a collision, an explosion, anything that blocks the channel for other vessels to safely enter and exit the port, pollution incidents — we’re kind of worried about the whole gamut,” Grable said. The economic stakes are colossal, with Grable noting that about $5.4 trillion in commerce flows through U.S. ports annually, so even a small disruption can cause major delays. Experts warn that cyberattacks against ships may not require highly advanced skills. Malicious code is already widely available, while AI can help attackers identify vulnerable, internet-facing systems and speed up attacks. In some vessels, satellite internet may be separated from critical systems by little more than a firewall, with navigation, propulsion, steering and ballast sharing the same network. Experts recommend network segmentation, phishing protection and basic cyber hygiene. Cyber access to a ship could create risks similar to remote hijacking, experts warn. However, taking full control of a supertanker is unlikely. A more realistic threat is disrupting critical systems such as navigation or propulsion, potentially making the vessel unsafe or causing it to run aground. Back to the attack on the two oil tankers, the U.S. has not publicly stated who is behind either cyberattack, but Iranian state media began pushing content around the VL Prosperity incident before U.S. authorities even acknowledged the boarding. Four days after Mehr’s initial report, Iran’s Tasnim News Agency published an article with the headline, “No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?” DuBose stressed that the Iranian narrative remains unverified, cautioning that Iranian‑linked actors are often quick to oversell their cyber influence. Attributing a cyberattack is very complex and can take weeks or even months. Investigators usually study how the attackers operated, looking at their tactics, techniques and procedures, often called TTPs. These patterns can act like digital fingerprints and help connect an attack to known threat groups. The growing concern is that ships are becoming more connected. Satellite communications and links between IT networks and onboard control systems can create new entry points for attackers. Experts say the industry should take this risk seriously, but not assume that every ship can simply be taken over remotely. Because maritime infrastructure is critical, governments are also introducing basic cybersecurity requirements for the sector. For ship owners and operators, the message is simple: pay attention to cybersecurity and strengthen the systems that protect critical onboard operations. Follow me on Twitter: @securityaffairs and Facebook and Mastodon (SecurityAffairs – hacking, newsletter)

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.