Culprit Unknown: When Cyber Attacks Threaten Oil Tankers and US Authorities Respond
The United States Coast Guard and the Federal Bureau of Investigations' advanced cyber threat teams confirm a joint operation on threatened oil tanker on route to the United States. With Iranian state media contradicting US evidence, the impact on navigation remains concerning.

After a month of speculation, the United States Coast Guard (USCG) has confirmed that they, in addition to the Federal Bureau of Investigations (FBI), launched a successful boarding operation on an oil tanker in late August.
After Action Report: VLCC Cyber Attack
On the 15th of September, during a media briefing, the USCG confirmed the occurrence of an operation on the 21st of August run jointly between the USCG and the FBI. The operation, currently publicly unnamed, aimed at and was successful in boarding the Liberian-flagged Very Large Crude Carrier (VLCC) VL Prosperity on its voyage to Galveston, Texas USA.
The 333-metre long vessel was transporting approximately 2.3 million barrels of crude oil before it was boarded by US agents.
The joint operation was undergone with little to no risk due to the proximity of the vessel to US ports in addition to a fully cooperative crew and the vessel is currently being held near Galveston Port.
Break
This operation represents a major escalation in US-centred maritime operations, yet it was not unexpected due to the history of the specific vessel.
Iranian Report Contradicts US Claims
Earlier in the month of August, the Iranian state-controlled news agency Mehr News reported a communications breakdown with the VL Prosperity as it was navigating the Strait of Gibraltar. This outage, later confirmed by the USCG, was due to an unspecified cyberattack on the ship’s network as it was transiting the Strait of Gibraltar after departing from the Sidi Kerir Port in Egypt.
While unconfirmed by the USCG, Mehr News Agency reported that the hackers gained control of the ship’s propulsion, navigation, and cargo systems through a cyber penetration of the engine-room systems. If this information is to be trusted and verified, this would signal a much more destructive and invasive capability of the hackers and would therefore open a major vulnerability in vessel security.
What has been confirmed by the relevant authorities is the communication outage. The hackers were able to shut off communications for nearly 30 hours, which is when the USCG and FBI were involved. Due to the port of destination and the cargo onboard, the Coast Guard Cyber Protection Team as well as the FBI Cyber Action Team intervened and launched their boarding operation.

Scrubbing the Deck: USCG and FBI Teams Launch Forensic Investigation
Following this successful action, the teams launched a full forensic operation on the vessel’s operational technology (OT), information technology (IT), and satellite communications (SatCom) systems in order to eradicate the cyber threat.
Most recently, the USCG and FBI have both informed the public that the vessel no longer remains vulnerable and there are no operational disruptions or dangers to crew or public.
The vessel’s managing company, the South Korean-based HMM Ocean Service Co., Ltd. confirmed the boarding of the vessel but have yet to announce any further information at this time.
What troubles the USCG and the United States in general was the second vessel which suffered a similar cyber attack on August 24th, which was then promptly boarded by US officials for a forensic assessment.
These attacks, which have not been claimed by a specific group nor linked to one, signify a dangerous evolution in the US/Iran war as the control and flow of crude oil remains a critical element of the war effort. Through an already hostile Strait of Hormuz and concurrently the Red Sea, the criticality of Egypt’s ports has become a top priority.

No End in Sight: US/Iran Conflict Continues to Impact Maritime Navigation and Trade
Yet, neither Iran nor any group hostile to the West has claimed responsibility for this attack. Additionally, US officials have said that no operations nor the flow of crude oil has been impacted by the boarding operations and that the cyber threats no longer affect the vessels attacked.
The impact on communications is threatening and therefore ship captains must be vigilant when transiting precarious regions; however, the possibility of a cyber attack on the engine systems presents a much more worrying future. With the Strait of Gibraltar already understood to be a GNSS interference corridor, maintaining a high degree of caution is advised.
While it is unlikely that US officials will confirm a breach of engine IT systems on US-bound vessels during a time of heightened geopolitical turmoil, the deployment of USCG and FBI teams already signals a level of criticality. With satellite and GPS systems understood to be chronically soft targets for cyber attacks, monitoring bridge systems by crew members is advised.
This time, both vessels remain afloat and without damage to crew or cargo; however, these attacks have demonstrated that targeting oil tankers is not off the table for certain bad actors. It is imperative that ship captains and crew remain vigilant regarding their IT/OT systems and to report any and all suspicious occurrences to the relevant authorities.
STOP BOARDINGS
Because your crew's safety cannot depend on methods that fail 90% of the time.
Don't let your crew become the next statistic.
Ready to upgrade your maritime security?
Get a free pre-voyage risk assessment and discover why our barriers have never failed to prevent unauthorised boarding.
Sources:
UKMTO
https://www.gurufocus.com/news/9082987/vl-prosperity-investigated-for-cyber-attack-by-us-coast-guard
https://maritimeoptima.com/public/vessels/pages/imo:9683697/mmsi:636023890/VL_PROSPERITY.html https://www.theatlantic.com/international/2026/05/why-irans-leaders-think-theyve-won/687325/


Comments