news.mlab.sh
Back to the feed
threat-intel

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

High
Summary

Two oil tankers traveling to Texas were boarded by US Coast Guard and FBI personnel after cyberattacks disrupted their operations. The attacks, allegedly originating on August 7th, involved intrusion into engine room systems, slowing coolant flow, and interfering with fuel delivery, while also impacting navigation and cargo systems. The incidents are under investigation, with concerns raised about potential Iranian involvement, though investigators are urging caution against overstating Iranian cyber capabilities. The US Coast Guard has established a dedicated Office of Maritime Cybersecurity Policy to address vulnerabilities in the maritime sector.

Two oil tankers traveling to Texas were boarded by US Coast Guard and FBI personnel after cyberattacks disrupted their operations. The attacks, allegedly originating on August 7th, involved intrusion into engine room systems, slowing coolant flow, and interfering with fuel delivery, while also impacting navigation and cargo systems. The incidents are under investigation, with concerns raised about potential Iranian involvement, though investigators are urging caution against overstating Iranian cyber capabilities. The US Coast Guard has established a dedicated Office of Maritime Cybersecurity Policy to address vulnerabilities in the maritime sector.

Iran’s Mehr News Agency reported on August 20 that the cyberattack had allegedly occurred on August 7 as the tanker passed through the Strait of Gibraltar. Citing a crew member, the Iranian outlet said the intrusion reached the engine room, with hackers slowing coolant flow, raising engine speed and interfering with fuel delivery.

The Coast Guard has not publicly linked the incident to Iran. Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, told CBS News that investigators did find evidence of a malicious cyber actor after reviewing the vessel’s IT and other onboard systems. She noted that nothing uncovered during the inspection suggested the tanker was unsafe to operate.

One day after Mehr’s report, a team that included Coast Guard cyber specialists, law enforcement, a vessel inspector, and FBI Cyber Action Team members boarded the VL Prosperity on August 24. The second ship was boarded on August 24 as well.

The cybersecurity community has long warned that the maritime sector’s reliance on aging, unmanaged OT systems, satellite communications, and connected IoT devices leaves both vessels and ports dangerously exposed to cyberattack. Attackers can exploit WiFi, HF radio, and SATCOM links — or simply an infected USB stick — to gain access, with successful compromise potentially granting remote control over a ship’s throttle, rudder, or navigation systems. Beyond ransomware, which has already disrupted shipping operations, experts point to even more severe scenarios such as GPS spoofing, AIS manipulation to disguise a vessel’s true location, or deliberately running a ship aground to block a critical waterway.

Given that roughly 80% of global goods move by sea, a targeted attack could trigger billions of dollars in losses and cascading supply shortages. The US Coast Guard has established a dedicated Office of Maritime Cybersecurity Policy to address vulnerabilities in the maritime sector.

Read the full article at SecurityWeek