U.S. authorities recently intervened in a cybersecurity breach aboard two oil tankers bound for the United States. Between August 21 and 24, teams from the FBI and Coast Guard boarded the vessels in the Gulf of Mexico after signs emerged that their network systems had been compromised. Concerns centered on navigation, propulsion, and cargo-control systems possibly being tampered with. The boardings were part of efforts to secure the ships’ operational and IT integrity following indications of compromise.
One of the targeted vessels has been identified as the VL Prosperity, a massive 333-meter tanker capable of carrying over two million barrels of oil. Intelligence suggests it was hacked while en route from Egypt to the U.S. on August 7. During the breach, hackers allegedly interrupted the ship’s fuel-management and speed controls and caused a communications blackout lasting more than a day. It remains unclear who orchestrated the attack, though U.S. authorities are investigating potential Iranian involvement.
The joint agencies’ statement noted that despite the severity of the cybersecurity concerns, there were no reported operational breakdowns, safety risks to crew members, or environmental damage. The captain, shipborne crew, and shore-based company personnel all cooperated fully throughout the investigation. Officials have not officially named the second vessel involved in the incident.
Why Tankers Are Increasing Targets
Oil tankers are complex systems with extensive technological infrastructure—for navigation, propulsion, cargo handling, and communications. That complexity expands the attack surface for potential cyber threats. The incident underscores how maritime logistics, already vulnerable due to global supply chain pressures, now face the added risk of malicious cyber interference.
This case joins a growing list of suspected state-linked cyberattacks. Recent cyber incidents believed to be tied to Iran include breaches of medical device firms, mass transit players, and water infrastructure across the United States. U.S. agencies have described many of these as “opportunistic” attacks, suggesting a broader pattern of probing and exploiting loosely protected systems.
Though the perpetrators have not been confirmed, the involvement of Iran is being explored given past patterns of behavior. If substantiated, this incident could represent a new escalation in how adversaries target critical maritime infrastructure and international shipping.
What this means going forward is that shipping companies and maritime authorities will have to invest heavily in cybersecurity for onboard networks. Detecting and responding to breaches early, especially threats to propulsion or navigation, will be essential to prevent both physical and environmental harm. Monitoring geopolitical motivations for such cyberattacks will also be crucial for national security.