US Coast Guard and FBI board Texas-bound supertankers following mid-ocean cyberattacks
4. Sec
The U.S. Coast Guard and the FBI deployed specialized cyber response units to board two foreign-flagged energy tankers off the coast of Texas following indications that malicious actors breached their onboard networks. The joint maritime interventions, conducted offshore in the Gulf of Mexico on August 21 and August 24, 2026, were initiated after investigators detected unauthorized intrusion activity affecting the vessels' information technology (IT) and operational technology (OT) systems.

Mid-Transit Compromise and Mid-Ocean Disruption
One of the affected vessels was identified as the VL Prosperity, a 1,093-foot Liberian-flagged crude oil supertanker capable of carrying 2.3 million barrels of oil, transiting from Egypt’s Sidi Kerir terminal to Galveston, Texas.
According to reports and public vessel-tracking data, the supertanker experienced severe network abnormalities while transiting near the Strait of Gibraltar:
30-Hour Communications Blackout: The vessel suffered a complete loss of communications lasting over 30 hours during its Atlantic transit.
Disruption of Engine and Navigation Systems: State media reports from Iran's Mehr News Agency claimed hackers gained remote access to the engine room, interfering with fuel delivery, slowing engine cooling flow, and increasing engine speed alongside navigation and cargo controls.
A second energy carrier bound for U.S. ports was similarly boarded on August 24 by a multi-agency tactical team comprising Coast Guard inspectors, cyber specialists, and FBI Cyber Action Team operators.
US Authorities Confirm Malicious Activity Without Official Attribution
In a statement, Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, confirmed that multi-agency teams boarded the VL Prosperity offshore for four days, uncovering definitive evidence of malicious cyber activity within the ship's networks. However, U.S. officials emphasized that the vessels remained operational and safe, reporting no physical damage, vessel instability, environmental spills, or injuries to the crew.
While Iranian state media published detailed accounts of the breach before U.S. agencies publicly acknowledged the boarding operations, federal law enforcement has not formally attributed the cyberattacks to Tehran or any specific state-sponsored threat group.
Cybersecurity experts cautioned that Iranian-linked entities frequently exaggerate their cyber influence, noting that forensic attribution remains ongoing.
Maritime OT Vulnerabilities and Industrial Security Implications
The incident underscores escalating systemic risks across global maritime supply chains, where modern commercial ships rely on internet-connected satellite links, automated ballast controls, and digital navigation suites. Security researchers highlighted that many commercial vessels lack robust network segmentation between consumer-facing satellite Wi-Fi links and critical OT networks governing propulsion and steering, often separated by only a single firewall.
The Coast Guard confirmed that its Cyber Protection Team has executed 40 to 50 similar offshore cyber inspection missions over the past year, prompting the agency to launch a dedicated Office of Maritime Cybersecurity Policy to enforce stricter network isolation standards across international energy fleets.












