Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
Two oil tankers bound for Texas were boarded by US Coast Guard and FBI personnel after cyberattacks disrupted their voyages. The VL Prosperity, a Liberian-flagged crude tanker, experienced malicious cyber activity including interference with engine and navigation systems and a 30-hour communications outage. Investigations found evidence of malicious cyber actors but no public attribution to Iran or other state actors. The Coast Guard noted the tankers remained safe to operate despite the disruptions. These incidents highlight ongoing cyber threats to the maritime sector, which relies on aging operational technology and connected systems vulnerable to attack.
AI Analysis
Technical Summary
In August 2026, two oil tankers en route to Texas were subject to cyberattacks that disrupted their operations. The VL Prosperity was boarded by US Coast Guard and FBI teams after evidence of malicious cyber activity was found affecting engine room controls, navigation, cargo systems, and communications. The attackers reportedly slowed coolant flow, increased engine speed, interfered with fuel delivery, and cut off communications for about 30 hours. While Iranian media reported the incident and suggested Iranian involvement, US authorities have not publicly attributed the attacks to Iran or any other actor. Investigations continue to determine connections between the incidents and responsible parties. The Coast Guard emphasized that the tankers were not unsafe to operate. These events underscore the vulnerabilities in maritime OT and communication systems, which can be exploited to degrade vessel operations and pose risks to global shipping.
Potential Impact
The cyberattacks caused operational disruptions on two oil tankers, including interference with engine controls, navigation, cargo systems, and communications outages lasting approximately 30 hours. Despite these disruptions, authorities confirmed the vessels remained safe to operate. The incidents demonstrate the potential for cyber actors to degrade maritime vessel operations, which could impact shipping logistics and supply chains. No confirmed attribution or evidence of physical damage or loss of control was reported.
Mitigation Recommendations
No official patch or fix applies as these are cyber incidents involving operational technology on maritime vessels. The US Coast Guard and FBI have conducted onboard investigations and continue to assess the threat. The Coast Guard has established a dedicated Office of Maritime Cybersecurity Policy to develop and implement cybersecurity policies for the marine transportation system. Operators should ensure robust cybersecurity measures for OT and communication systems, including monitoring for unauthorized access and securing satellite and radio communications. Given the ongoing investigations, no specific mitigation actions contradicting official guidance are recommended at this time.
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
Description
Two oil tankers bound for Texas were boarded by US Coast Guard and FBI personnel after cyberattacks disrupted their voyages. The VL Prosperity, a Liberian-flagged crude tanker, experienced malicious cyber activity including interference with engine and navigation systems and a 30-hour communications outage. Investigations found evidence of malicious cyber actors but no public attribution to Iran or other state actors. The Coast Guard noted the tankers remained safe to operate despite the disruptions. These incidents highlight ongoing cyber threats to the maritime sector, which relies on aging operational technology and connected systems vulnerable to attack.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In August 2026, two oil tankers en route to Texas were subject to cyberattacks that disrupted their operations. The VL Prosperity was boarded by US Coast Guard and FBI teams after evidence of malicious cyber activity was found affecting engine room controls, navigation, cargo systems, and communications. The attackers reportedly slowed coolant flow, increased engine speed, interfered with fuel delivery, and cut off communications for about 30 hours. While Iranian media reported the incident and suggested Iranian involvement, US authorities have not publicly attributed the attacks to Iran or any other actor. Investigations continue to determine connections between the incidents and responsible parties. The Coast Guard emphasized that the tankers were not unsafe to operate. These events underscore the vulnerabilities in maritime OT and communication systems, which can be exploited to degrade vessel operations and pose risks to global shipping.
Potential Impact
The cyberattacks caused operational disruptions on two oil tankers, including interference with engine controls, navigation, cargo systems, and communications outages lasting approximately 30 hours. Despite these disruptions, authorities confirmed the vessels remained safe to operate. The incidents demonstrate the potential for cyber actors to degrade maritime vessel operations, which could impact shipping logistics and supply chains. No confirmed attribution or evidence of physical damage or loss of control was reported.
Defensive Guidance
No official patch or fix applies as these are cyber incidents involving operational technology on maritime vessels. The US Coast Guard and FBI have conducted onboard investigations and continue to assess the threat. The Coast Guard has established a dedicated Office of Maritime Cybersecurity Policy to develop and implement cybersecurity policies for the marine transportation system. Operators should ensure robust cybersecurity measures for OT and communication systems, including monitoring for unauthorized access and securing satellite and radio communications. Given the ongoing investigations, no specific mitigation actions contradicting official guidance are recommended at this time.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/cyberattacks-on-two-oil-tankers-prompt-coast-guard-fbi-to-board-vessels/","fetched":true,"fetchedAt":"2026-09-17T17:31:39.878Z","wordCount":1281}
Threat ID: 6aac23fb55bf5e2cf5ad8b74
Added to database: 09/17/2026, 17:31:39 UTC
Last enriched: 09/17/2026, 17:31:45 UTC
Last updated: 09/17/2026, 22:39:34 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.