Skip to content

Security1 publisher3 min readPublished

Coast Guard and FBI cyber teams boarded a tanker in the Gulf of Mexico on August 21

The Coast Guard sent cyber specialists, a vessel inspector and FBI operators onto a tanker underway in the Gulf of Mexico after indications of compromise, and says it has so far found no danger to the crew or the environment.

The Watch · Security desk

Photograph accompanying Coast Guard and FBI cyber teams boarded a tanker in the Gulf of Mexico on August 21
Photo: abcnews.com

What happened

  • The U.S. Coast Guard confirmed it boarded a tanker transiting the Gulf of Mexico in August after hackers attacked the vessel's network.
  • The stated purpose was to ensure the integrity of the vessel's operational and information technology systems after indications the network had been compromised by foreign cyber actors.
  • The Coast Guard said there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.
  • Mehr reported that the Liberian-flagged VL Prosperity, sailing from an Egyptian port to a U.S. port, was attacked on August 7 while transiting the Strait of Gibraltar.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • precedent Sending a vessel inspector aboard alongside a Cyber Protection Team puts network compromise inside the same inspection regime that covers hulls and machinery, so owners of U.S.-bound ships can expect federal investigators on the deck plates while they are still triaging.
  • contradiction The Coast Guard's assessment and Mehr's account cannot both be complete: one reports nothing broken, the other reports 30 hours without communications and an attacker raising engine speed.
  • exposure If the Gibraltar timeline holds, a ship can be compromised mid-voyage in one hemisphere and arrive at a U.S. terminal with the intrusion still aboard, which makes the receiving port the last party to learn of it.
  • decision An operator weighing whether to notify now has to price a physical response, and the Coast Guard's refusal to say which ship it boarded means the record gives owners little sense of what a boarding costs in time or disclosure.

A vessel inspector went aboard with the cyber specialists. The Coast Guard spokesperson said the August 21 party was "comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators," and that it embarked "to conduct a comprehensive cyber security boarding and investigation" [4]. The inspector's presence means the ship's physical condition and its networks were examined in the same visit [4].

The Coast Guard confirmed the boarding after the Wall Street Journal reported that at least two tankers headed for the U.S. had been hit with cyberattacks [2]. Bloomberg identified one of them as VL Prosperity and reported the ship is now off the coast of Texas [7][14]. Mehr, an Iranian government-backed outlet, said VL Prosperity lost communications for 30 hours [11]. A crew member told Mehr that the attackers were allegedly able to increase the engine speed and disable the ship's fuel and engine-oil tank [12].

That last claim is the operationally serious one, and it rests on one unnamed crew member in a state-backed outlet. The Coast Guard did not answer questions about the nature of the attack, who was potentially behind it, or whether the August 21 boarding involved VL Prosperity [8]. No hacking group has taken credit, and Mehr cited Russian analysts who tied the incident to the military conflict between the U.S. and Iran [13]. The FBI did not respond to requests for comment, and several other agencies referred Recorded Future News to the Coast Guard [5]. Fourteen days separate the August 7 attack date Mehr reported from the boarding the Coast Guard confirmed [1].

That August 7 date falls one day after North Carolina Ports reported an intrusion of its own, on August 6, and shifted to manual operations [15][2]. A spokesperson said the port's IT system was "hacked by an outside actor or group," and that the port enacted a contingency plan and contacted multiple state agencies as well as the Coast Guard [16]. Nothing published connects the two events.

Five years of port and shipping intrusions have mostly looked like extortion aimed at shore-side IT [17]. The Port of Seattle refused to pay a ransom in 2024 after disruption at the city's airport and seaport [18]. Royal Dirkzwager, DNV and several European ports were hit with ransomware in 2023 [19]. Oiltanking and Mabanaft declared force majeure in 2022, and Expeditors International said an attack crippled some of its operating systems for months [20][21]. This case is a ship underway with compromise the Coast Guard attributes to foreign cyber actors, and the federal response was to put a team on the deck plates [3][4].

The Coast Guard said it is still working with port operators, vessel owners and local maritime stakeholders to "ensure port operations continue safely and without interruption" [22].

What to watch

  • Whether the Coast Guard confirms VL Prosperity was the vessel boarded on August 21, or identifies the second ship the Wall Street Journal says was boarded on August 24.
  • Any Coast Guard directive or advisory telling US-bound vessels to inspect the shipboard IT and OT systems the boarding party examined.
  • An attribution beyond the phrase "foreign cyber actors": no group has claimed the attack, and the Russian-analyst link to the U.S.-Iran conflict comes only through Mehr.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories