Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Tanker cyberattacks prompt Coast Guard and FBI to board two Texas-bound ships

Investigators found malicious cyber activity on a Liberian-flagged crude tanker but no sign it was unsafe to navigate; Iranian claims of engine sabotage are unverified.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Coast Guard and FBI teams boarded the tanker VL Prosperity on August 21; a second, unnamed Texas-bound vessel was boarded on August 24, The Wall Street Journal reported.
  • 2A Coast Guard admiral said investigators found malicious cyber activity but no evidence the ship had become unsafe to navigate.
  • 3Iranian media claims of engine and fuel-system tampering are unverified, and the U.S. has not attributed the attacks.

The news

Tanker cyberattacks led U.S. Coast Guard and FBI cyber teams to board two Texas-bound vessels in August, CBS News reported on September 16. Investigators found malicious cyber activity aboard one crude tanker but no evidence it was unsafe to navigate.

According to CBS News, the VL Prosperity, a 1,093-foot Liberian-flagged crude tanker with capacity for about 2.3 million barrels, left Egypt's Sidi Kerir oil terminal on August 1 bound for Galveston, Texas. Iran's Mehr News Agency reported that the attack occurred on August 7 near the Strait of Gibraltar. Coast Guard and FBI teams, including members of the FBI's Cyber Action Team, boarded the ship on August 21 and spent four days aboard.

A second, unnamed vessel was boarded on August 24, SecurityWeek reported, citing The Wall Street Journal. CBS called both ships energy tankers and SecurityWeek called them oil tankers, so the second vessel's type is unconfirmed. Both were bound for Texas. U.S. officials are investigating whether the two incidents are connected.

Rear Admiral Amy Grable of Coast Guard Cyber Command told CBS News that investigators did find malicious cyber activity, but that response teams saw no evidence the ship had become unsafe to navigate. Asked generally how sophisticated an attacker would need to be to manipulate machinery aboard a modern tanker, she said "not necessarily that sophisticated," noting that malicious source code is available. The boarding was one of roughly 40 to 50 missions the Coast Guard's Cyber Protection Team has carried out over the past year, CBS reported.

The incident first surfaced on August 20, when Iran's Mehr News Agency, citing an unnamed crew member, claimed hackers had interfered with engine-room systems, slowing coolant flow, raising engine speed and disrupting fuel delivery, and had cut communications for about 30 hours. Those claims have not been confirmed by U.S. officials, and CBS reported that no public determination has been made about Iranian involvement.

The numbers

VL Prosperity length
1,093 feet
Tanker capacity
About 2.3 million barrels
Days investigators spent aboard
4
Coast Guard cyber missions in past year
About 40–50

Why CEOs should care

For energy buyers, commodity traders and shippers, a cyber incident on a chartered vessel is a supply-chain event. Even without physical damage, a boarding and a four-day investigation can delay discharge and raise questions about cargo integrity and navigation data. Ask charter partners and ship managers how onboard IT and operational technology (the systems that run engines, fuel and navigation) are segmented, patched and monitored, and what their incident reporting obligations are.

For CISOs at ports, terminals and logistics firms, the admiral's general remark that manipulating tanker machinery need not take a sophisticated attacker matters most. If widely available malicious code can reach ship systems, basic controls deserve scrutiny: shared credentials, flat networks and unmonitored remote access. Review how vessels and shore systems connect to your networks, and who can push files or updates to them.

For CFOs and risk officers, check how marine and cyber insurance policies treat an incident that starts in ship IT but causes delay or loss at a terminal. Clarify any gaps between those policies with brokers before a claim, not after.

The bigger picture

The case exposes a gap in U.S. rules. The Coast Guard's cybersecurity rule for the marine transportation system, published in January 2025 and effective July 16, 2025, covers U.S.-flagged vessels and U.S. facilities. It excludes foreign-flagged vessels such as the VL Prosperity; in the rule, the Coast Guard said covering them during ongoing international discussions would disrupt port state control, and that it may revisit the rule as International Maritime Organization standards develop. A 2017 IMO resolution does call for cyber risks to be addressed in ships' ISM Code safety management systems from 2021. But for foreign ships calling at U.S. ports, federal cyber teams are in effect doing hands-on inspections that the U.S. rule does not require.

The sequence of disclosure is also instructive. Iran's Mehr News Agency published the first account on August 20, about two weeks after the August 7 date it gave for the attack, and almost a month before U.S. officials described their findings publicly. In incidents with a geopolitical edge, the first narrative may come from a party with an interest in amplifying it. Energy and shipping firms should prepare statements that acknowledge claims without confirming details they cannot yet verify.

What’s next

Watch for any formal attribution by U.S. agencies, for the name and type of the second vessel, and for whether the Coast Guard issues advisories to vessel operators based on what its teams found. More specific IMO cyber requirements, or a Coast Guard move to extend its rule to foreign-flagged ships, would also shift obligations for charterers and port operators.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

U.S. Coast GuardFBIMaritime securityCritical infrastructure

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.