06
Tue, Oct

Cyberattacks on two US-bound tankers put cyber risk back in the spotlight

Cyberattacks on two US-bound tankers put cyber risk back in the spotlight

Maritime cyber security
Cyberattacks on two US-bound tankers put cyber risk back in the spotlight

Two energy tankers bound for Texas were hit by cyberattacks last month while underway, prompting US Coast Guard and FBI teams to board both vessels for multi-day investigations.

One of the ships, the VL Prosperity, is a 1,093-foot Liberian-flagged crude carrier that was heading for Galveston. Iranian state media named the vessel shortly after the incident and claimed hackers had penetrated its propulsion, navigation and cargo systems, cutting off communications for roughly 30 hours.

US authorities have stopped short of publicly attributing the attacks to Iran, but Rear Admiral Amy Grable, who commands US Coast Guard Cyber Command, confirmed to CBS News that responders uncovered signs of malicious cyber activity once they began examining the ship’s IT and onboard systems.

What is known so far

The VL Prosperity is a supertanker with capacity for about 2.3 million barrels of crude. Vessel-tracking data shows it left Egypt’s Sidi Kerir terminal on August 1 en route to Galveston. According to US officials, the ship slowed near the Strait of Gibraltar around the time of the reported attack before resuming its crossing to the United States.

Iran’s Mehr News Agency reported on August 20 that the vessel had been targeted on August 7 while transiting the Strait. Citing an unnamed crew member, Mehr claimed hackers had breached the engine room, disrupted cooling flow, pushed up engine speed and tampered with fuel systems.

Rob Lee, CEO of industrial cybersecurity firm Dragos, said the technical details in the Iranian account were plausible and consistent with how such systems could realistically be manipulated — while cautioning that attribution has not been established.

The following day, August 21, a joint team of Coast Guard cyber specialists, law enforcement officers, a vessel inspector and FBI Cyber Action Team operators boarded the tanker and remained aboard for four days.

Inside the investigation

Grable said the boarding was one of an estimated 40 to 50 missions the Coast Guard’s Cyber Protection Team has carried out over the past year, triggered after interagency partners flagged the incident. Investigators focused on hunting for malware and tracing how far the intrusion had spread through the ship’s IT infrastructure.

Her central concern, she said, is the connection between IT networks and the operational systems that govern propulsion, navigation and other functions critical to a vessel’s safety. Investigators gathered data for further analysis, and the Coast Guard intends to give the ship’s owner recommendations for closing the vulnerabilities involved. Importantly, Grable noted that responders found no evidence the vessel had become unsafe to operate at the time of boarding.

A widening attack surface

The episode underscores a broader shift in maritime risk. As commercial vessels increasingly depend on networked systems for navigation, propulsion, steering, ballast and other machinery, the potential for a cyber intrusion to spill over into physical consequences grows accordingly.

Grable warned that highly connected vessels are inherently more exposed, raising the risk of outcomes ranging from a blocked waterway to a pollution incident. She said authorities are particularly alert to the danger of an attack near a US port, a collision, an explosion, or any incident that could shut down a channel — given that an estimated $5.4 trillion in commerce moves through American ports each year.

Even a modest disruption, such as forcing a port to switch to manual operations, can cascade into significant delays for tankers and cargo vessels alike.

Perhaps most striking was Grable’s assessment of how accessible the tools for such an attack have become. Malicious source code capable of enabling this kind of intrusion is already circulating, she said, and artificial intelligence is compressing the timeline in which operators need to respond.

Her recommendation was straightforward: prioritise network segmentation, guard against phishing, and maintain basic cyber hygiene, since foundational precautions would head off most incidents of this kind.

Questions over attribution

US officials have not formally attributed either attack, even as Iranian state media moved quickly to publicise the VL Prosperity incident — in some cases before American authorities had acknowledged the boarding publicly. Iran’s Tasnim News Agency followed with a pointed headline days later, framing the episode as evidence that US vessels were newly vulnerable.

DuBose cautioned that the Iranian narrative remains unverified and that state-linked actors often have an incentive to inflate their cyber capabilities. Grable noted that attribution typically relies on comparing an attacker’s tactics, techniques and procedures against known threat-actor profiles, effectively digital fingerprints built up over time, a process that can take weeks or months to complete.

The industry takeaway

For Coast Guard Cyber Command, the underlying trend is what matters most: as vessels adopt satellite communications and link IT networks to onboard control systems, they create more entry points exposed to the open internet — and more opportunities for malicious actors to gain access.

DuBose said the sector should take the threat seriously without overcorrecting into the assumption that every vessel is now vulnerable to remote takeover, adding that regulators have been steadily raising baseline cybersecurity requirements across maritime infrastructure given how critical it is.

Grable’s message to owners and operators was unambiguous: this is an issue that demands sustained attention across the industry.

Content Original Link:

Original Source SAFETY4SEA www.safety4sea.com

" target="_blank">

Original Source SAFETY4SEA www.safety4sea.com

SILVER ADVERTISERS

BRONZE ADVERTISERS

Infomarine banners

Advertise in Maritime Directory

Publishers

Publishers