The FBI has confirmed cyberattacks against two commercial tankers travelling toward Texas. US officials are investigating whether Iran or an aligned group played a role, although authorities have not publicly identified the attackers.

FBI Confirms Two Tanker Cyberattacks

The FBI confirmed that cyber incidents affected two separate commercial vessels in August.

US cyber teams conducted investigations aboard the ships on August 21 and August 24. Both vessels had travelled through the Strait of Gibraltar while heading toward ports in Texas.

One tanker carried almost 2.3 million barrels of oil. Meanwhile, the second vessel planned to collect liquefied petroleum gas from another Texas port.

US officials are reportedly considering whether Iran or an Iran-aligned group could have conducted the attacks. However, the investigation remains active, and authorities have not formally attributed either incident.

Cyber Teams Board VL Prosperity

Authorities identified one of the affected vessels as VL Prosperity, a Liberian-flagged crude oil tanker.

The ship left Egypt’s Sidi Kerir Oil Terminal on August 1. It listed Galveston, Texas, as its destination and planned to arrive on August 24.

VL Prosperity measures 333 metres and has a deadweight capacity of 319,547 tonnes. It entered the Gulf of Mexico after travelling from the Mediterranean.

However, three days before its expected arrival, a specialised US team boarded the vessel to investigate a major network compromise.

The team included Coast Guard law enforcement personnel, a vessel inspector and members of the Coast Guard Cyber Protection Team. FBI Cyber Action Team operators also joined the operation.

Foreign Actors Compromise Vessel Network

The Coast Guard said investigators found indications that foreign cyber actors had compromised the vessel’s network.

The joint boarding aimed to assess both operational technology and information technology systems. These systems support navigation, communications and machinery aboard modern commercial vessels.

Cyber specialists inspected the ship and worked to secure its infrastructure. According to the Coast Guard, the operation continued for more than three days.

Authorities have not released technical details about the attack vector. They also have not explained how the hackers initially accessed the vessel.

Second Tanker Was Heading Toward Texas

The FBI also confirmed an investigation into another tanker cyberattack.

The second vessel, named Kohaku, measures 227 metres and sails under the Marshall Islands flag. It planned to travel to a Texas port to load liquefied petroleum gas.

Like VL Prosperity, Kohaku reportedly passed through the Strait of Gibraltar. Vessel tracking data later showed it anchored near Malta.

Authorities have not revealed whether the same attackers targeted both ships. Nevertheless, the similar routes, destinations and timing have prompted a coordinated investigation.

Strait of Gibraltar May Have Strategic Importance

Both vessels travelled through the Strait of Gibraltar, which connects the Mediterranean Sea with the Atlantic Ocean between Spain and Morocco.

Around 300 ships use the passage each day. Therefore, it represents one of the world’s most important maritime chokepoints.

Traffic through Gibraltar has also increased amid disruption around the Strait of Hormuz. As a result, the route carries growing strategic importance for global energy shipments.

Investigators may examine whether the ships’ routes and cargo made them attractive targets. However, US authorities have not publicly confirmed a motive.

Iranian Report Claims Communications Failed

Iran’s state-owned Mehr News Agency identified VL Prosperity before US authorities publicly named the vessel.

Citing an unnamed crew member, the outlet claimed that the tanker lost all communications for 30 hours. It also alleged that the attackers accessed engine-room systems.

According to the report, the attackers reduced engine cooling flow and increased engine speed. The outlet further claimed they disabled systems connected to fuel and engine-oil tanks.

However, US authorities have not confirmed these technical claims. Therefore, the report should not be treated as an official account of the incident.

Mehr did not say that a specific group had claimed responsibility. Nevertheless, its coverage presented the attack as a possible warning from Iran’s so-called Resistance Front.

US Investigates Possible Iranian Connection

The Coast Guard described the incident as malicious cyber activity by foreign actors. However, it did not name the country or group responsible.

Other reports said US officials are examining possible ties to Iran or an aligned organisation.

The timing of the attacks and the vessels’ routes may form part of that assessment. Moreover, Iranian state media’s early identification of VL Prosperity may attract investigators’ attention.

Still, none of these factors proves Iranian involvement. A formal attribution would require stronger technical, intelligence and operational evidence.

Coast Guard Reports No Physical Impact

The Coast Guard said it had received no reports of vessel instability or physical danger to crew members.

Authorities also found no environmental damage or continued disruption to ship operations. Cyber teams reportedly mitigated the identified threats.

Additionally, the Coast Guard praised the tanker’s captain, crew and corporate personnel for cooperating with the investigation.

The agency continues to communicate with vessel owners, port operators and local maritime organisations. These efforts aim to keep port activities running safely and without interruption.

Maritime Operators Urged to Seek Assistance

The Coast Guard encouraged maritime companies to request anonymous cyber assistance before an incident escalates.

Commercial vessels increasingly rely on connected operational systems. Consequently, a network intrusion can create risks beyond stolen data or unavailable communications.

Attackers may attempt to interfere with navigation, propulsion, fuel management or engine monitoring. Even limited access could disrupt schedules and affect port operations.

The two tanker cyberattacks show why shipping companies must separate critical operational systems from general networks. They should also restrict remote access, monitor unusual activity and maintain tested recovery procedures.


0 responses to “FBI Investigates Cyberattacks on Two Texas-Bound Tankers”