U.S. Authorities Investigate Foreign Cyberattacks Targeting Gulf-Bound Vessels

The Aug. 21 boarding involved a specialized team comprising Coast Guard law-enforcement personnel, a vessel inspector, Coast Guard Cyber Protection Team members and FBI Cyber Action Team operators. The team examined both operational technology and information-technology systems and worked with the ship’s crew and corporate operators to remove the threat.
The vessel identified in Iranian media reports appears to have been the VL Prosperity, a 333-meter Liberian-flagged very large crude carrier capable of carrying about 2.3 million barrels of oil and reportedly bound for Galveston, Texas.
Iran’s Mehr News Agency alleged that attackers penetrated the VL Prosperity’s engine-room systems, reduced engine-cooling flow, increased engine speed and interfered with fuel and lubricating-oil systems. The report cited an unnamed crew member, and the allegations have not been independently confirmed.
Iranian state media portrayed the incident as evidence of a broader vulnerability in maritime security; Tasnim News Agency published the headline, “No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?”
The U.S. Coast Guard and FBI boarded at least two foreign-flagged vessels heading to the Gulf Coast on August 21 and 24 after their computer networks were compromised by foreign cyber actors. AP News reported that authorities found no operational damage, but the incident has raised alarms about vulnerabilities in American maritime security and whether hostile nations are exploiting cyber attacks to destabilize critical infrastructure.
One vessel, identified as the VL Prosperity, a massive oil tanker capable of carrying 2.3 million barrels, was apparently targeted with sophisticated cyber attacks. AP News reported that Iranian state media claimed attackers penetrated the ship's engine-room systems and reduced cooling flow while increasing engine speed. The allegations, attributed to an unnamed crew member, have not been independently verified.
The VL Prosperity, a Liberian-flagged vessel, was reportedly bound for Galveston, Texas when it transited the Strait of Gibraltar. One ship lost communications for more than 30 hours during the incidents. WTOP confirmed that authorities examined both operational and information-technology systems aboard both vessels.
The August 21 boarding involved Coast Guard law-enforcement personnel, a vessel inspector, members of the Coast Guard Cyber Protection Team, and FBI Cyber Action Team operators. WTOP reported that the joint team worked directly with ship crews and corporate operators to remove cyber threats. No operational disruption, vessel instability, or danger to crews occurred during the incidents.
Authorities have not yet attributed the attacks to a specific actor. AP News noted that U.S. officials are investigating whether Iran or another adversary tried to exploit the incidents to widen tensions in the Middle East conflict. The timing and coordination of the two separate boardings suggest a deliberate pattern.
Iranian state media quickly amplified reports about the suspected cyberattacks. AP News reported that Tasnim News Agency published the headline, "No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?" — framing the incident as evidence of broader weaknesses in U.S. maritime security. Mehr News Agency alleged specific technical sabotage of fuel and lubricating-oil systems.
The rapid amplification by Iranian outlets suggests the attacks are part of a broader information strategy. Whether Iran was directly involved in the cyber compromise or simply exploiting existing vulnerabilities remains unclear. Winnipeg Free Press confirmed that authorities found no environmental damage or crew endangerment from the incidents.
Publishers
26
Articles
193
Reach
219