Coast Guard Cyber Teams and FBI Operators Boarded a 2.3-Million-Barrel Supertanker Bound for Galveston After It Went Dark for 30 Hours in the Strait of Gibraltar. Iran's Media Says Hackers Took Over the Engine Room.
The VL Prosperity, a 333-meter Liberian-flagged crude carrier sailing from Egypt, was boarded Aug. 21 to investigate a cyberattack reported two weeks earlier. The U.S. has not said who did it, and the Coast Guard says there was no damage, spill or danger to the crew.
A team of Coast Guard law enforcement specialists, a vessel inspector, members of the Coast Guard's Cyber Protection Team and operators from the FBI's Cyber Action Team boarded a very large crude carrier inbound to Galveston, Texas, on Aug. 21 to investigate a cyberattack on the ship, CBS News reported Tuesday. The vessel was the VL Prosperity, a 333-meter Liberian-flagged tanker with room for roughly 2.3 million barrels of oil.
The boarding was the first public confirmation from the U.S. government that the incident was real. Iranian state-aligned outlets, including the Mehr and Tasnim news agencies, had reported on Aug. 20 that the ship was attacked on Aug. 7 while sailing from Egypt's Sidi Kerir terminal toward the United States, and that it lost all communications for 30 hours in the Strait of Gibraltar. Citing a crew member, those reports claimed the attackers got into the engine-room systems, cut the flow of engine cooling, pushed up engine speed and disabled the fuel and lubricating-oil tanks. No group has claimed responsibility, and Washington has not attributed the breach to anyone.
The Coast Guard, in a statement, was careful about what it would and would not say. "Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts," it said. It did not describe what the cyber team found on board, whether malware was recovered, or whether the Iranian accounts of engine manipulation were accurate. The FBI referred questions to the Coast Guard.
What makes the case unusual is not that a ship was hacked but that the U.S. sent cyber specialists to meet it at the sea buoy. Modern tankers run on interconnected operational technology: propulsion, steering, ballast, cargo pumps and navigation are all networked, often with remote access for shore-side engineers and the manufacturers of the equipment. That connectivity is what lets a shipping company monitor a fleet from an office in Athens or Singapore. It is also what would let a hostile actor with the right credentials or the right exploit reach into an engine room from anywhere on Earth. The Coast Guard has warned about exactly this since at least 2024, when it and the White House issued new maritime cybersecurity rules, and it stood up dedicated Cyber Protection Teams to board and assess vessels.
The timing sharpens the concern. The United States has been at war with Iran since Feb. 28, the Strait of Hormuz has been contested for months, and Saudi Arabia's East-West pipeline is still out of service after attacks earlier this month. A tanker carrying Egyptian-terminal crude to the Gulf Coast is precisely the kind of cargo that matters more when Middle East supply is disrupted. Whether the Iranian coverage of the attack reflects inside knowledge or opportunistic amplification is one of the questions investigators will want answered.
For now the ship is the story. The Coast Guard has not announced any restrictions on the vessel or its cargo. But the fact that a supertanker can lose contact with the world for more than a day, then be met by federal cyber operators at an American port, is a reminder of how much of the global oil trade now depends on software that was never designed to be attacked.
Originally reported by CBS News.