Security3 publishers3 min readPublished
Coast Guard cyber teams found malicious activity aboard Texas-bound tanker and second vessel in Gulf of Mexico
Coast Guard Cyber Command says its teams found malicious cyber activity aboard both hulls after offshore boardings in the Gulf of Mexico, while the engine-room manipulation and the 30-hour communications outage rest on one Iranian state media report.
The Watch · Security desk

What happened
- Coast Guard and FBI teams carried out joint offshore boardings of two US-bound commercial ships in the Gulf of Mexico on Aug. 21 and Aug. 24 after indications that both vessels' networks were compromised.
- One ship was the VL Prosperity, a 1,093-foot Liberian-flagged crude supertanker carrying about 2.3 million barrels of oil to Galveston, Texas.
- Iran's Mehr News Agency reported on Aug. 20 that intruders had reached the engine room on Aug. 7 near the Strait of Gibraltar, slowing coolant flow, raising engine speed and interfering with fuel delivery.
- The agencies' joint statement reported no operational disruptions, vessel instability, physical danger to crews or environmental impacts, and said port operations were continuing without interruption.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction An owner reading the Iranian account and an owner reading the joint statement get two different incidents: engine-room manipulation on one side, no operational disruption on the other, with no US attribution to settle which is closer.
- cost A network-compromise indication on an inbound hull now buys four days of federal investigators aboard a laden supertanker, and the owner and charterer absorb the schedule.
- precedent US agencies will now put boarding teams on foreign-flagged vessels offshore on compromise indications alone, using authorities granted by the 2024 executive order.
The engine-room interference and the roughly 30-hour communications outage rest on Mehr News Agency's Aug. 20 report, sourced to an unnamed crew member [7][8]. Iranian state media was circulating the story before US authorities acknowledged the boarding [27]. Mehr published 13 days after the date it gave for the attack [29].
The Coast Guard has not publicly linked either attack to Iran, and investigators are still working out whether the two incidents are connected [12]. "They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity," Grable told CBS News [11]. She said nothing found during the inspection suggested the tanker was unsafe to operate [13]. The boarding party arrived on Aug. 21, one day after Mehr published, and stayed four days [9]. The second ship was boarded on Aug. 24, according to The Wall Street Journal [10].
Quinton DuBose, a former Coast Guard cyber official, disputed the idea that hackers could take full command of a supertanker and said the realistic risk is degrading enough individual systems to make safe operation difficult, SecurityWeek reported [21]. He urged caution about the Iranian coverage, noting that Iran-linked actors have a history of overstating their cyber capabilities [22]. The Wall Street Journal reported in June that Coast Guard cyber teams have been investigating dark fleets carrying sanctioned Iranian and Russian oil, which rely on digital masking and carry enhanced cyber risk [25].
Aboard, the teams hunted for malware and looked specifically at whether the vessels' IT systems were connected to propulsion, navigation and other critical safety systems [19]. On some vessels, according to Security Affairs, satellite internet is separated from those systems by little more than a firewall, with navigation, propulsion, steering and ballast sharing one network [20].
Grable put the boarding among roughly 40 to 50 missions the Coast Guard's Cyber Protection Team has run in the past year [14]. That is a vessel every seven to nine days [15]. She also said about $5.4 trillion in commerce moves through US ports annually [16], which works out to close to $15 billion a day [17]. "Of course we're worried about a collision, an explosion, anything that blocks the channel for other vessels to safely enter and exit the port, pollution incidents," Grable said [18].
The boardings came days after the Coast Guard announced an Office of Maritime Cybersecurity Policy as its central authority for cyber safety and security policy across the marine transportation system [23]. Its authority to respond offshore dates to an executive order signed in 2024, which cited the risk that a maritime cyber incident could cause cascading harm to the global supply chain [24].
What to watch
- Whether the Coast Guard and FBI say the two intrusions are linked, and whether either is attributed to a state actor.
- Whether the Coast Guard publishes indicators or a marine safety information bulletin drawn from the two boardings.
- Whether the new Office of Maritime Cybersecurity Policy sets IT-to-OT segmentation expectations for vessels calling at US ports.