135
Views

USCG and FBI Investigate Cyberattacks on US-Bound Tankers

tanker
USCG and FBI confirmed they are investigating possible cyberattacks on US-bound tankers

Published Sep 16, 2026 1:22 PM by The Maritime Executive

U.S. officials are confirming an ongoing investigation into an apparent cyberattack on at least one or two tankers bound for the United States last month. The Federal Bureau of Investigation and the U.S. Coast Guard said the vessels’ crews reported the incidents while saying that there was no immediate danger to the crew or the environment.

According to a joint statement to The Wall Street Journal, the investigations “were designed to ensure the integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised by foreign actors ... Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”

The Coast Guard did not provide details, but suspicions have quickly centered on Iran after the Iranian media began reporting incidents in early August. The Tasnim agency, which is reported to be associated with the Islamic Revolutionary Guard Corps, ran a story on August 20 saying the tanker VL Prosperity (IMO 9683697) “was targeted by a major cyberattack in the Strait of Gibraltar, and all of its communications were cut off for 30 hours.” 

It claimed to have information from a crewmember aboard the Liberian-flagged tanker that “the attackers infiltrated the engine-room systems, reduced the engine’s cooling flow, increased the engine speed, and disabled the ship’s fuel and engine-oil tank.”

Similar reports appeared in other Iranian news outlets, including Mehr News Agency. Tasnim followed up with a story entitled “No American Vessel is Safe Anymore: Will Cannons Give Way to Codes?

The tanker, which is 319,547 dwt, is managed by HMM Ocean Services and was heading for Galveston, Texas. CBS News reports HMM confirmed its vessel was under investigation. The reports said the vessel experienced the problems while transiting the Strait of Gibraltar. Media reports are also suggesting that a second, so far unnamed, LNG carrier also notified the authorities of a suspected cyberattack. 

A specialized team of Coast Guard law-enforcement personnel, a vessel inspector, Coast Guard Cyber Protection Team members and FBI Cyber Action Team were reported to have boarded an unnamed ship when it arrived in Texas. The media says the first inspection took place on August 21 and was followed days later on August 24. AIS signals show the VL Prosperity is still at anchor off Galveston.

Classification societies and security analysts have long warned about the potential for cyberattacks as vessels have become more integrated and connected through cyber systems. GPS spoofing and jamming were long cited as one key danger, with at least one tanker in the Red Sea blaming jamming for contributing to its grounding, but analysts also warn of the dangers of malware and ransomware. The International Maritime Organization issued its first Maritime Cyber Risk Management in Safety Management Systems directive in June 2017 on shipping-related operational, safety, or security failures as a consequence of information or systems being corrupted, lost, or compromised.