The U.S. Coast Guard said it boarded a tanker transiting the Gulf of Mexico in August after the vessel’s network was attacked by hackers. A Coast Guard spokesperson confirmed the incident after the Wall Street Journal reported that at least two tankers headed for the U.S. were hit with cyberattacks. Bloomberg News identified one of the tankers as VL Prosperity, and Iranian government-backed news outlet Mehr said the ship lost communications for 30 hours. The FBI did not respond to requests for comment and several other agencies directed Recorded Future News to the U.S. Coast Guard, which said officials boarded the ship to “ensure integrity of the vessel’s operational and information technology systems following indications that the vessel’s network were compromised by foreign cyber actors.” “On August 21, a highly specialized team — comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators — embarked the vessel to conduct a comprehensive cyber security boarding and investigation,” the spokesperson said. “Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.” The U.S. Coast Guard did not respond to questions about the nature of the attack, who was potentially behind it or whether the August 21 boarding involved VL Prosperity. The Wall Street Journal said another ship was boarded on August 24. Mehr reported that VL Prosperity was flying under a Liberian flag from a port in Egypt headed to a port in the United States when it was attacked on August 7 while transiting the Strait of Gibraltar. A crew member told Mehr that the attackers were allegedly able to increase the engine speed and disable the ship’s fuel and engine-oil tank. The news outlet cited Russian analysts who claimed the incident was connected to the current military conflict between the U.S. and Iran but no hacking group has taken credit for the incident. Bloomberg reported that VL Prosperity is currently located off the coast of Texas. The U.S. Coast Guard spokesperson said it is still working with port operators, vessel owners, and local maritime stakeholders to “ensure port operations continue safely and without interruption.” One day before the alleged attack on VL Prosperity, North Carolina Ports reported a cyberattack that forced a shift to manual operations. A spokesperson for North Carolina Ports said at the time that its IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard. Ports in the U.S., Europe and Asia have been repeatedly targeted by ransomware gangs over the last five years as many shift to incorporate digital operations. In 2024, the Port of Seattle refused to pay a ransom to cybercriminals that caused issues at the city’s airport and seaport ahead of the Labor Day holiday. Several ports in Europe as well as large shipping companies Royal Dirkzwager and DNV were hit with ransomware in 2023 while oil companies Oiltanking and Mabanaft declared force majeure after cyberattacks in 2022 and logistics and freight forwarding giant Expeditors International similarly announced a cyberattack that crippled some of its operating systems for months.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.