Thursday, September 17, 2026
The Daily Signal
World news, clustered and summarised by machine
Edition of 17-09-2026 Morning edition
Trends this edition
The Second Trump Era Reshapes the World 2
All →

Cyberattacks Trigger Maritime Security Probe

Thursday, September 17, 2026
Sources cbsnews.com 2straitstimes.com 1
Image for cluster 4
Image prompt

Coast Guard and federal investigators boarding a large foreign-flagged commercial tanker near a Texas port, examining bridge consoles and secure communications equipment during a maritime cybersecurity inspection, photojournalistic documentary photography, natural daylight under a hazy coastal sky, realistic ship textures and safety gear, captured with a 35mm lens, restrained professional mood emphasizing vigilance and critical infrastructure protection.

Summary

U.S. authorities are investigating suspected cyberattacks against commercial energy tankers and monitoring potential threats involving nearly 20 ships worldwide. The Coast Guard and FBI boarded two foreign-flagged vessels bound for Texas after detecting possible compromises in their information-technology and operational systems, including the Liberian-flagged VL Prosperity. Iranian media alleged that attackers manipulated communications, propulsion, navigation, engine cooling, fuel and cargo systems, but U.S. officials have not verified those claims or attributed the incidents to Iran or any other actor. Authorities reported no confirmed loss of control, operational disruption, danger to crews, vessel instability or environmental damage. The incidents highlight growing cybersecurity risks created by internet-connected maritime systems, aging operational technology and common attack routes such as malware-infected storage devices, phishing and malicious downloads. Experts warn that even limited disruption to critical ship systems could endanger navigation, block ports, damage supply chains and affect the roughly $5.4 trillion in annual commerce moving through U.S. ports, prompting calls for network segmentation, patching and stronger cyber hygiene.

Key Points

  • The Coast Guard and FBI boarded two inbound foreign-flagged tankers in August after suspected compromises of their information-technology and operational networks, including the Texas-bound VL Prosperity.
  • U.S. agencies are tracking possible cyberthreats involving nearly 20 ships and have asked some vessels to provide advance notice before entering U.S. ports.
  • Iranian reports claimed attackers accessed or manipulated propulsion, navigation, communications, engine and fuel systems, but the allegations and any connection to Iran remain unverified.
  • No confirmed takeover, operational disruption, crew injuries, vessel instability or environmental damage was reported, although investigators found evidence of malicious cyber activity on at least one vessel.
  • Maritime experts warn that connected ship systems and aging equipment could enable attacks that disrupt global supply chains, while recommending segmentation, vulnerability patching, phishing defenses and basic cyber hygiene.

Articles in this Cluster

Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk? - CBS News

The U.S. Coast Guard and FBI boarded two Texas-bound energy tankers after cyberattacks disrupted the vessels while they were traveling toward the United States. One ship, the 1,093-foot Liberian-flagged VL Prosperity, was reportedly attacked near the Strait of Gibraltar. Iranian state media claimed hackers accessed the tanker’s propulsion, navigation, cargo and fuel systems, although U.S. authorities have not attributed the incident to Iran or any other actor. Coast Guard Cyber Command commander Rear Adm. Amy Grable said investigators found evidence of malicious cyber activity but did not find indications that the vessel was unsafe to navigate. The Coast Guard and FBI spent four days examining the VL Prosperity’s information-technology systems for malware and other signs of compromise. Investigators are assessing whether the two tanker incidents were connected and whether a foreign adversary was responsible. The Coast Guard plans to provide the ship’s owner with recommendations for patching vulnerabilities. Experts warn that the growing connectivity of commercial vessels creates serious risks. Modern ships may use internet-linked systems for navigation, propulsion, steering, ballast and other critical functions. A successful intrusion could cause a collision, pollution incident, explosion, blocked waterway or major port disruption. Because approximately $5.4 trillion in commerce moves through U.S. ports annually, even a short shift to manual operations could create substantial economic consequences. Grable said attackers may not need exceptional technical skills because malicious code is widely available and artificial intelligence can accelerate the search for vulnerable systems. Experts emphasized network segmentation, protection against phishing and basic cyber hygiene. While a complete remote takeover of a supertanker may be difficult, former Coast Guard cyber official Quinton DuBose said disrupting critical subsystems could make a ship unsafe to operate. Iranian media reports about the incident remain unverified.
Entities: VL Prosperity, U.S. Coast Guard Cyber Command, Federal Bureau of Investigation (FBI), Rear Adm. Amy Grable, Rob LeeTone: analyticalSentiment: negativeIntent: analyze

Coast Guard, FBI boarded Texas-bound oil tanker after ship's network was potentially breached - CBS News

U.S. Coast Guard personnel and FBI cyber specialists boarded a Texas-bound oil tanker in the Atlantic on August 21 after authorities determined that its network may have been compromised by a foreign actor. The Coast Guard did not identify the vessel, but Iranian media named it as the Liberian-flagged VL Prosperity, a 333-meter very large crude carrier capable of transporting approximately 2.3 million barrels of oil. Public vessel data indicated that the ship was traveling toward Galveston, Texas, while HMM Ocean Service Co., Ltd., the South Korean company managing it, confirmed the boarding. Iranian state media reported that the tanker lost communications for about 30 hours on August 7 while sailing from Egypt’s Sidi Kerir terminal to the United States. Mehr News Agency, citing an unnamed crew member, alleged that attackers accessed engine-room systems, altered engine cooling and speed, and interfered with fuel and lubricating-oil systems. The Coast Guard has not confirmed those specific claims or attributed the suspected intrusion to Iran or any other actor. The boarding team included Coast Guard law-enforcement personnel, a vessel inspector, Coast Guard Cyber Protection Team members, and FBI Cyber Action Team operators. They examined the tanker’s operational and information-technology systems and worked with the crew and corporate operators to remove the threat. Authorities said there were no reported operational disruptions, vessel instability, physical danger to the crew, or environmental impacts. The incident highlights the risks posed by interconnected maritime operational technology. A successful intrusion into propulsion, navigation, or cargo systems could theoretically allow an attacker to manipulate a large tanker’s movement or machinery, although the article notes that such a scenario is unlikely. Iranian media subsequently portrayed the incident as evidence of a new cyber front in the conflict with the United States, but U.S. officials have not publicly confirmed the extent or origin of the breach.
Entities: U.S. Coast Guard, Federal Bureau of Investigation (FBI), VL Prosperity, HMM Ocean Service Co., Ltd., Atlantic OceanTone: analyticalSentiment: neutralIntent: inform

US tracking cyberthreats targeting nearly 20 ships worldwide | The Straits Times

US government agencies are monitoring possible cyberthreats involving nearly 20 ships worldwide, according to officials familiar with the matter. The US Coast Guard has asked the vessels to provide advance notice if they intend to enter a US port, although their destinations and cargo manifests were not immediately known. The Coast Guard is coordinating with the FBI and Department of Homeland Security units. Several commercial vessels were targeted in potential cyberattacks in late August. Officials said the attackers did not appear to take control of the ships, and the Coast Guard reported no operational disruptions, vessel instability, physical danger to crews or environmental damage. The agency nevertheless boarded two inbound foreign-flagged vessels in the Gulf of Mexico on Aug 21 and Aug 24 after indications that their operational and information technology networks had been compromised. The incidents come as maritime cybersecurity concerns increase. Modern ships rely heavily on digital systems for navigation, communications and other operations, while many operational systems use aging equipment that is difficult to update. Security researchers warn that attackers could exploit these weaknesses to disrupt global supply chains. Maritime cybersecurity firm CyberOwl reported a sharp increase in ship-related incidents during the first half of the year; more than half of the attempted intrusions it detected involved malware introduced through storage devices, while others involved internet downloads or phishing. The article also cites previous incidents, including a suspected attack on an MSC vessel in France and claimed disruptions to communications systems on more than 100 Iranian oil tankers. Experts say such attacks may be intended not only to cause direct damage but also to create uncertainty and instability among governments, companies and crews.
Entities: US Coast Guard, Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), US Department of Homeland Security, Gulf of MexicoTone: analyticalSentiment: negativeIntent: inform