The US Coast Guard and the FBI boarded two US-bound oil tankers in the Gulf of Mexico in late August after both ships showed signs their networks had been compromised at sea. One of them, the VL Prosperity, is a 333-metre crude carrier rated for more than two million barrels. It was hacked on August 7 while sailing from Egypt, lost communications for over a day, and saw interference with speed and fuel systems.
Reporting on the incidents describes navigation, propulsion and cargo systems being reached on at least one vessel. The agencies say there were no operational disruptions, no vessel instability, no danger to crews and no environmental impact. A third ship, a liquefied gas carrier, was hit off the Italian coast. US officials are said to be watching roughly twenty vessels worldwide.
The Attribution Question
Investigators are looking at Iran. Nothing is confirmed, and the shipping sector has plenty of other plausible actors, from ransomware crews who don’t care what they’ve landed on to states with an interest in energy flows. What makes the Iranian hypothesis worth taking seriously is the recent pattern around it: intrusions tied to Iranian-linked operators at a medical device manufacturer, at the Los Angeles transit system, and at more than a hundred US water utilities.
Those are all soft operational technology targets in civilian infrastructure. A tanker fits the pattern precisely. It’s OT, it’s lightly defended, it’s far from help, and hitting it creates leverage without creating a casualty event that forces a military response.
Why Ships Are This Easy
A modern tanker is a floating industrial plant with a satellite uplink. The bridge systems, the engine control, the cargo and ballast automation and the crew’s own network often share infrastructure that was installed at delivery and never meaningfully updated. Class societies certify the equipment, not its patch level. Remote vendor access for engine diagnostics is normal and often permanently on.
The satcom terminal is the front door and it stays open, because voyage planning, weather routing, charter communication and crew welfare traffic all depend on it. Segmentation between that link and the OT network exists on the drawing and frequently not on the ship.
What the Sector Actually Buys Now
IMO rules have required cyber risk management in safety systems since 2021, and the industry treated that as a documentation exercise. Two boarded tankers change the conversation because they change who’s asking. Charterers will start writing cyber clauses into terms. War risk and hull underwriters will ask what’s on the vessel’s network before they quote, and cyber exclusions in marine policies will get tested in a way they haven’t been.
The addressable market here is large and slow. There are somewhere north of sixty thousand merchant vessels in the world fleet, each needing network segmentation, monitoring that works over a constrained satellite link, and a retrofit programme that can only happen in drydock. That favours the OT security vendors with marine certification and the classification societies moving into advisory, rather than the enterprise security names.
Nobody was hurt this time. That’s the only comfortable sentence in the story.