A cyber investigation aboard two tankers in the Gulf of Mexico
On 15 September 2026 the US Coast Guard acknowledged that a federal cyber team had boarded an oil tanker bound for Texas. The next day several sources reported that two vessels were involved, then that nearly twenty merchant ships were under particular watch. The case had begun a month earlier, with an account published in Tehran.
This article is also available in French.
The story arrived… before the facts
On 20 August the Iranian news agency Tasnim put out a dispatch saying that a US-bound tanker had suffered a cyberattack while transiting the Strait of Gibraltar on 7 August [1]. The report is a detailed one: thirty hours without satellite or radio communications, then an intrusion into the engine-room control systems, engine speed raised, cooling flow reduced, monitoring of the fuel and lubricating oil tanks disabled. Mehr then relayed the dispatch and the trade press followed, with nothing further to add.
For three weeks the story existed only through its own republication: nothing from an owner, from the manager, from the registry (Liberian), from the port authority (Gibraltar) or from the authorities (Spanish or Moroccan).
Then, on 15 September, a Coast Guard spokesperson answered questions from Bloomberg [2]. Coast Guard personnel and the Federal Bureau of Investigation had boarded a foreign-flagged vessel on 21 August, following indications that its network had been compromised. The master, the crew and the shore staff cooperated, and the agency added that no operational disruption or injury had been recorded. Neither the Coast Guard nor the FBI names the ship. The reporting and the manager point to the VL Prosperity, a very large crude carrier of 333 metres registered in Liberia under IMO 9683697, loaded in Egypt and expected in Texas.
The joint statement of 16 September
A joint statement by the FBI and the Coast Guard, published on 16 September, widens the frame [3]. It tells us that the two agencies responded on 21 and 24 August to reported network breaches aboard two foreign-flagged commercial oil tankers. Both vessels showed indications that their networks had been compromised by cyberattacks. An interagency team boarded each of them in the Gulf of Mexico to assess the integrity of their operational and information technology systems. The statement adds that there are no reports of operational disruptions, vessel instability, physical danger to crews or environmental impacts, and it identifies nobody as responsible.
The composition of the team is published for the first time [4]. It was made up of Coast Guard law enforcement personnel and, among others, a Coast Guard Cyber Protection Team, for which this is hardly a first1, a vessel inspector and operators of the FBI Cyber Action Team. They embarked on 21 August for what the Coast Guard calls a comprehensive cyber security boarding and investigation.
The same day, Rear Admiral Amy Grable, who commands Coast Guard Cyber Command, told CBS that the investigators did find malicious cyber activity aboard [5]. She added that an attack of this kind need not be especially sophisticated, and that the event she most fears would be a vessel blocking a waterway or an incident with an environmental impact, neither of which happened here.
The engine-room account is still unconfirmed
The technical manager of the first vessel, HMM Ocean Service, confirmed the boarding of the ship it operates. The company says it applies rigorous cyber protocols and is awaiting the conclusive report of the American authorities [6]. The Coast Guard has since cleared the vessel for normal operations.
None of this validates the compromises first described. The agencies say they assessed the integrity of operational and information technology systems, without saying anything about the result. Rear Admiral Grable placed the malicious activity in the vessel’s computer systems without naming a function. Propulsion, steering gear, cargo control, ECDIS and AIS are untouched by anything published.
Two claims are left that do not overlap: a shipboard network compromise established by the authorities, and a machinery casualty described by a single source.
No attribution for now
No responsible party is named in the joint statement. It is plainly too early, and the teams need time to investigate. American officials quoted anonymously say that the possibility of Iranian involvement, or of another actor seeking to exploit the ongoing conflict, forms part of the investigation [7]. That is a line of inquiry, and it commits nothing further. That Iranian state media published the case before any American acknowledgement says something about how the information travelled, but leaves the question of the author open.
The second vessel, the Kohaku
The joint statement names neither ship. The second is, in all likelihood, the Kohaku, a 91,000 cubic metre gas carrier built in 2023 and registered in the Marshall Islands under IMO 9932608. The Wall Street Journal names her alongside the VL Prosperity [8], and ship registers confirm her particulars. She was heading for the United States to load liquefied petroleum gas, which clears up the gap with the reports that described a liquefied natural gas carrier.
What the joint statement adds about this ship is not a small thing. Until 16 September the second case rested on a newspaper report that two tankers had been attacked, with a compromise established for only one of them. The two agencies now write that the networks of both vessels showed indications of compromise. The second file moves from reporting to an official finding, with no particular shipboard system named.
Nearly twenty ships under watch
The American government is also tracking cyber threats against nearly twenty merchant ships worldwide, Bloomberg reported on 16 September [9]. The Coast Guard tracks them with the FBI and Department of Homeland Security units, and it has asked to be given advance notice if any of those ships plans to enter a US port. An official of the Cybersecurity and Infrastructure Security Agency adds that several merchant vessels were targeted in potential cyberattacks in late August, and that the attackers did not appear to have taken control of the ships themselves.
The advance-notification request is the part that bears most directly on an operator, because it turns a threat picture into an instrument of port state control. A ship on that list arrives in the United States with a likely boarding ahead of her, and with the risk of a captain of the port order that delays her entry or attaches conditions to it. A missed berth slot and a few days alongside doing nothing usually cost more than the incident itself. The request also sits on top of the notice of arrival already required ninety-six hours before the call, which leaves little room to discover the situation late.
The flag and operator of these ships go undisclosed, and nothing suggests that an owner is told when one of its vessels is on the list: the first sign may be the Coast Guard calling. The legal basis of the request is no clearer, and a marine safety information bulletin does not carry the same weight as an informal call to the managers. It sits alongside the framework the Coast Guard has been rolling out since 2025 on the cybersecurity of vessels and facilities, whose assessment and waiver strand I covered earlier.
The vector is still unknown
The file still says nothing about the vector, the code used, the entry point or the persistence, for either vessel. An operator would need them to check whether it is exposed the same way. The conclusive report that HMM Ocean Service is waiting for may contain them. Nothing says it will be public.
Sources
- [1] Tasnim News Agency, US-bound oil tanker targeted in cyberattack, 20 August 2026
- [2] Reuters, US Coast Guard boarded Texas-bound oil tanker to investigate cyberattack, Bloomberg News reports, 15 September 2026
- [3] CyberScoop, Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks, 16 September 2026
- [4] The Record, Coast Guard, FBI boarded tanker after attack by “foreign cyber actors”, 16 September 2026
- [5] CBS News, Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?, 16 September 2026
- [6] CBS News, Coast Guard, FBI boarded Texas-bound commercial oil tanker to investigate cyberattack, 16 September 2026
- [7] ABC News, Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks, 16 September 2026
- [8] The Wall Street Journal, U.S. Probes Cyberattacks on Energy Tankers Bound for American Coast, 16 September 2026
- [9] gCaptain, U.S. tracks cyber threats against nearly 20 ships worldwide, 16 September 2026
The precedent goes back to February 2019. A deep-draft vessel inbound to the Port of New York and New Jersey had itself reported an incident affecting its shipboard network, and a Coast Guard-led interagency team went aboard to analyse that network and the essential control systems. It concluded that the malware had significantly degraded the computers without reaching those systems, and I wrote it up at the time. Seven years on, the arrangement is the same and the public conclusion stops in the same place: damage found on the information technology side, and nothing established about the essential systems. ↩︎