made using Leaflet

The Tanker Cyberattacks and the Exposed Merchant Fleet

In late August 2026, US Coast Guard and FBI cyber teams boarded two foreign tankers in the Gulf of Mexico because someone had broken into their networks somewhere between the Mediterranean and Texas. As far as I know, it is the first time US authorities have publicly confirmed boarding merchant ships for a cyber intrusion, and it will not be the last.

For years, ship hacking was mostly something researchers showed at conferences or that hit shipping companies' offices on land. The tanker cases are different: the intrusions happened on board, at sea, on ships carrying millions of barrels of crude and liquefied gas toward a major energy port. In this piece I set out what is known about the incidents, put them in the context of earlier attacks on merchant shipping, explain in plain terms how a ship gets hacked, and look at the rules that do and do not cover it.

A Coast Guard boarding team member climbs aboard an oil tanker off San Pedro, California, April 2026. Illustrative photo, not the tanker boardings in this article. US Coast Guard photo by PO3 Roberto Nieves (public domain, via DVIDS).


What happened

VL Prosperity. The first ship is the VL Prosperity, a Liberian-flagged crude oil tanker 333 metres long, carrying about 2.3 million barrels from Egypt to Galveston, Texas. The story did not come out through Washington. On 20 August, Iran's state-linked Mehr news agency reported that the ship had suffered "a major cyberattack" around 7 August while passing through the Strait of Gibraltar.

Citing an unnamed crew member, Mehr claimed the attackers got into the engine-room systems. They are said to have reduced cooling water flow, raised engine speed, interfered with the fuel and lubricating oil tank systems, and knocked out the ship's communications for about 30 hours. Mehr presented the attack as a message from Iran's "Resistance Front" that international waters have no immunity.

The Strait of Gibraltar from the International Space Station, 14 April 2023. About 300 ships pass through every day; both VL Prosperity and Vivit Africa LNG reported problems here. Photo: NASA Earth Observatory.

The boardings. On 21 August, the Coast Guard boarded Prosperity in the Gulf of Mexico, and on 24 August it boarded a second ship. The team was a mix of Coast Guard law enforcement, a Coast Guard Cyber Protection Team, a vessel inspector, and an FBI Cyber Action Team. The Prosperity boarding alone took four days. Rear Admiral Amy Grable, who commands Coast Guard Cyber Command, confirmed they found evidence of malicious cyber activity.

The second ship was not named officially. Cybernews identified it as the Kohaku, a 227-metre LPG tanker under the Marshall Islands flag, also bound for Texas and also reportedly compromised near Gibraltar.

The official line. The US account is much more modest than the Iranian one. According to the Coast Guard, "foreign cyber actors" compromised the networks of both ships, but there were "no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts." CISA, the US civilian cyber agency, added that the attackers "did not appear to have taken control of the vessels themselves." The agencies have not explained the gap between their version and Mehr's.

A third ship. In early September, the LNG carrier Vivit Africa LNG had loaded at Cameron LNG in Louisiana and was heading for the Adriatic LNG terminal near Rovigo, Italy. The ship is Korean-owned, Liberian-flagged, operated by H-Line Shipping and on charter to Vitol. Its automation is supplied by Kongsberg.

In an email to the trade publication Splash247, the crew claimed that attackers "gained temporary control of the steam pressure and safety valve systems" while the ship passed Gibraltar. In the Adriatic, they wrote, compromised tank pressure controls and pressure relief valves disrupted the handling of boil-off gas, the cargo that evaporates naturally in an LNG tank. According to the crew, that "significantly increases the risk of tank rupture and explosion." Splash247 has not verified these claims.

The official accounts are more cautious. The Italian Coast Guard said the master reported a malfunction in the systems that monitor cargo parameters, and that the cause "couldn't be identified." Kongsberg said it was "too early to draw conclusions." On 18 September the ship turned west toward Algeciras without delivering its cargo.

The wider picture. The US Department of Homeland Security has since confirmed that the Coast Guard is tracking about 20 vessels worldwide, and it is asking ships to notify it before they enter US ports. In the same period, in the first week of August, the North Carolina State Ports Authority was hit by a cyberattack. Gates at Wilmington, Morehead City, and the Charlotte inland port had to run manually for several days. Nobody has publicly linked that attack to the ships.

Table 1: Timeline

Not the first time

Merchant shipping has been hit by cyber incidents for more than a decade. What has changed is where the damage lands: the early cases mostly hit offices and cargo data on shore, while the recent ones reach the ship itself.

Antwerp, 2011 to 2013. For a Belgian reader, the classic case is close to home. Drug traffickers hired hackers to break into the systems of shipping companies at the Port of Antwerp, using malware and devices planted on terminals after break-ins. They used the access to track containers with drugs hidden in them and collect them before the legitimate owner could. Police seized 864 kg of heroin and hundreds of kilos of cocaine in 2013.

NotPetya, 2017. Malware hidden in a Ukrainian tax software update spread worldwide and shut down Maersk's IT systems for days. Terminals stopped, bookings had to be taken by hand, and Maersk put the cost at up to 300 million dollars. The ships kept sailing, but the company that ran them was blind.

Black Sea GNSS spoofing, 2017. In June 2017, more than 20 ships near Novorossiysk saw their GPS place them at an airport inland, while one was actually drifting more than 25 nautical miles away. The receivers still showed the position as accurate. Spoofing means sending fake satellite signals that a receiver accepts as real, and this was one of the first well-documented mass cases at sea.

Malware on a ship bound for New York, 2019. In February 2019, the Coast Guard found malware that had "significantly degraded" the computer systems of a deep-draught ship heading for New York and New Jersey. The essential control systems kept working. The inspectors found shared passwords, no antivirus, no separation between networks and no patching, and the crew knew about it.

Iran's own target lists, 2020. Documents leaked to Sky News in 2021 were said to come from an IRGC cyber unit called Shahid Kaveh. They looked at attacking ballast pump systems and two models of ship satellite terminals, with the note that disruption could cause "significant and irreparable damage to the vessel." Iran's embassy declined to comment.

DNV ShipManager, 2023. A ransomware attack on DNV's fleet management software in January 2023 affected about 1,000 ships of 70 customers. Ships could keep using the software offline, but the shore side was down for weeks.

GNSS jamming in the Gulf, 2025. On 17 June 2025, the VLCC Front Eagle and the tanker Adalynn collided near the Strait of Hormuz, during heavy GNSS interference linked to the Israel–Iran war. At the time, around 970 ships a day were reporting interference. The UAE authorities and the owner, Frontline, called it a navigational incident unrelated to the hostilities. Jamming means drowning out the satellite signal so the receiver gets nothing usable.

Iran's tankers hacked, 2025. In March 2025, and again in August, a group calling itself Lab Dookhtegan claimed to have cut the communications of dozens of ships of the National Iranian Tanker Company and IRISL. Researchers later traced the attack to Fanava, the Iranian company providing their satellite service. From there the attackers got full control of the onboard satellite terminals and wiped them. A Cydome researcher called it sabotage and not espionage. It shows that the same method can be turned against any fleet that relies on one service provider.

Growth in numbers. The Coast Guard's own annual report on maritime cyber trends, published in July 2026, counted 17% more maritime cyber incidents in 2025 than in 2024. Operational technology featured in 62% of its cyber missions, up from 46%. Operational technology, or OT, is the equipment that physically runs the ship: engines, steering, ballast, cargo pumps. Korean firm Cytur estimates that maritime cyberattacks roughly doubled in 2025.

Table 2: History

How a ship gets hacked

A modern merchant ship is a floating network. On one side is the office IT: email, crew Wi-Fi, planned maintenance software, cargo paperwork. On the other side is the OT: the engine control system, steering gear, ballast and cargo pumps, the integrated bridge with ECDIS (the electronic chart) and radar. In theory these sit apart. In practice they are often linked, because owners, makers and charterers want data from the engine room and cargo system sent ashore.

Rob Lee, chief executive of the industrial security firm Dragos, summed up the problem to CBS: "navigation, propulsion, ballast, steering, ship command, everything on one shared network." The main ways in are:

Satellite links. VSAT and, more and more, Starlink terminals connect the ship to the internet around the clock. Researchers at Pen Test Partners found satcom terminals reachable from the open internet with factory passwords such as admin/1234 as early as 2018. The Lab Dookhtegan attack went one step further and hacked the satellite service provider, reaching every ship it served at once.

Remote access by makers. Engine, automation and navigation suppliers often have remote access for diagnostics and software updates. That is a door into the OT side, and it is only as secure as the supplier's own systems.

USB sticks and laptops. Chart updates, crew laptops and service engineers' equipment are plugged into ship systems in port. The 2019 New York case shows how malware rides along.

Phishing ashore. The Coast Guard names phishing as the most common entry point. An attacker who takes over a company email or fleet management account can work toward the ships from there.

Unprotected radio signals. GPS and AIS have no authentication. Anyone with the right transmitter can jam them or feed in false data, without touching the ship's network at all.

Diagram 1: How to get in

Three of the five routes enter through the office network and only reach the engine room because IT and OT are linked; maker access goes straight in, and GPS and AIS can be attacked from outside.

Once inside, the old ship protocols do not help. Many bridge and engine systems still talk via NMEA 0183, a simple standard from the 1980s with no encryption or authentication. Pen Test Partners showed that by changing a single letter in a steering message, an R for right rudder into an L, you change the ship's course. Older ships also run software that can no longer be patched, and OT systems usually lack the antivirus or monitoring that office computers have. John Strand of Black Hills Information Security pointed to exactly that after the tanker boardings: maritime OT has no endpoint protection, which makes it an attractive target.

Getting into a network is not the same as steering a ship. Engine control systems have their own safety interlocks, and the crew can switch to local or manual control. That is likely why the US authorities stress that nobody took control of the tankers. But a crew that loses its communications for 30 hours, or its cargo monitoring on an LNG carrier, has a serious safety problem even without a hostile hand on the wheel.

Who is behind it, and why

Nobody has been officially named. According to the Wall Street Journal, US officials are looking at Iran or an Iran-aligned group, as well as the possibility that a third party is using the US–Iran tensions as cover. No hacker group has claimed the tanker attacks. Quinton DuBose, a former Coast Guard cyber official, pointed out that attribution means comparing the attackers' digital fingerprints with known groups, and that can take weeks or months.

The circumstantial picture is clear enough to explain the suspicion. Iranian state media broke the Prosperity story before the US did and framed it as a warning. The IRGC has studied ship systems as targets since at least 2020, according to the leaked Shahid Kaveh files. In September 2026, Anthropic reported that an Iran-linked actor had used its Claude AI model to compile targeting material on the US Navy, including research on vulnerabilities in maritime VSAT terminals, Cisco communications equipment and industrial control products. That report concerned the Navy, not merchant ships, and no link to the tankers has been shown. Iran's own fleet was itself hit by Lab Dookhtegan in 2025.

Not everyone reads the incidents the same way. Dahvid Schloss of Suzu Labs thinks the pattern looks more like reconnaissance, meaning mapping access for later use, than an attempt to cause damage now. Damon Small of Xcape argues that a 30-hour communications blackout is already a significant operational disruption for safe navigation.

State actors are not the only threat. Criminal ransomware groups go after shipping companies and their suppliers for money. In October 2025 the Rhysida group hit Furuno, the Japanese maker of bridge electronics. Organised crime uses hacking to move drugs through ports, as Antwerp found out. And activist hackers, sometimes fronting for a state, attack ships to make a political point.

The rulebook

There is no single binding international rule on ship cybersecurity. What exists is a patchwork of guidelines, class rules and national laws, and the three tankers fall through most of it.

IMO. Since 2021, IMO resolution MSC.428(98) requires shipowners to cover cyber risk in their Safety Management System under the ISM Code, the international code for safe ship operation. The detail is in non-binding guidelines, last revised in April 2025 (MSC-FAL.1/Circ.3/Rev.3). In 2025 the Maritime Safety Committee decided against prescriptive mandatory rules and endorsed work on a non-mandatory, goal-based cybersecurity code. In May 2026 that work was passed to the Facilitation Committee. No completion date has been set.

Classification societies. The IACS unified requirements UR E26 (cyber resilience of ships) and UR E27 (cyber resilience of onboard systems and equipment) are binding, but only for ships contracted for construction from 1 July 2024. The existing fleet, including ships like Prosperity, is not covered.

United States. A Coast Guard rule in force since July 2025 requires US-flagged ships and US port facilities to report cyber incidents, appoint a cybersecurity officer, train crews and, by July 2027, have an approved cyber plan. It does not apply to foreign-flagged ships, which make up the great majority of ships calling at US ports, including all three ships in this story.

European Union. The NIS2 directive brings shipping companies, port authorities and vessel traffic services under cybersecurity and incident reporting duties. Belgium transposed it in 2024, with the Centre for Cybersecurity Belgium as supervisor. NIS2 regulates companies, not individual ships.

Industry guidance. BIMCO, ICS and others publish guidelines and a cyber workbook for use on board. They are widely used but voluntary.

Table 3: Rules and Regulations

That leaves a large gap: an older, foreign-flagged tanker trading to the US or Europe is subject only to the general ISM duty and whatever its owner chooses to do.

What comes next

The people closest to the cases expect more. Corey Ranslem, chief executive of Dryad Global, said that a ship-centred cyberattack "is not that difficult to pull off" and that he expects these attacks "to continue and will expand in the very near future." Rear Admiral Grable warned that artificial intelligence "is accelerating the rate at which we need to take action", and Cytur expects AI to let less skilled attackers run more advanced campaigns.

Several developments are worth watching:

Stricter port entry. The Coast Guard is already asking ships to report before arrival and is watching about 20 vessels. Cyber declarations before arrival and more cyber inspections of foreign ships are a logical next step. European energy ports with crude and LNG terminals, Antwerp-Bruges and Rotterdam among them, face the same question.

From access to physical effect. If the reconnaissance reading is correct, the access gained is being kept for later. Grable named the risks of a forced switch to manual operation: collisions, pollution and blocked waterways. The Dali and the Key Bridge showed in 2024 what a loss of propulsion in a narrow channel can do, even without any hacker involved.

Pressure on the foreign-flag gap. The fact that the US rule does not apply to the very ships that were attacked will feed calls for port state requirements, and for faster IMO action.

Insurance. Hull and P&I insurers and charterers can be expected to ask more questions about OT security and to look again at how cyber losses are covered.

Satellite and supplier risk. The Lab Dookhtegan case and the Kongsberg question around Vivit Africa LNG both point to the supply chain. One compromised provider can affect a whole fleet.

For anyone on a ship's bridge, including pilots on board in port approaches, the practical consequence is a change in mindset. An unexplained change in engine response, a frozen display or a sudden loss of communications on a ship that recently crossed the Mediterranean may now have a cyber cause as well as a technical one. Basic seamanship remains the best defence: knowing how to switch to local control, cross-checking the GPS position by radar and visual bearings, and not relying on AIS alone.

Sources

The tanker incidents

gCaptain: Authorities Investigating Cyber Breaches Aboard Two U.S.-Bound Ships

Military Times / AP: Coast Guard boards US-bound vessels apparently compromised by hackers

CBS News: Coast Guard and FBI boarded 2 energy tankers due to cyberattacks

The Record: Coast Guard, FBI boarded tanker after attack by foreign cyber actors

TechCrunch: FBI, Coast Guard boarded hacked oil tankers

Cybernews: Tanker cyberattack hits two US-bound oil ships

Cybernews: 3rd tanker reports suspected cyberattack, 20 ships on US watch

Industrial Cyber: USCG, FBI assess OT and IT systems aboard two oil tankers

gCaptain: Another Tanker Suffers Failure as Crew Suspect Cyber Attack

Splash247: Crew claims hackers seized control of LNG carrier safety systems

Maritime Executive: Tanker burning off Khor Fakkan had shadow fleet ties

CyberScoop: Coast Guard monitoring North Carolina Ports cyberattack

Earlier incidents and research

SecurityWeek: Drug traffickers hacked shipping systems (Antwerp)

CNBC: Maersk says NotPetya could cost up to $300 million

Inside GNSS: Mass GPS spoofing in the Black Sea

Maritime Executive: USCG malware attack exposes cyber vulnerabilities at sea

Times of Israel: Secret files show alleged Iranian plans to sink ships using cyberattacks

The Record: Ransomware attack on maritime software impacts 1,000 ships

gCaptain: GPS jamming in Strait of Hormuz after tanker collision

Industrial Cyber: Lab Dookhtegan attack traced to Fanava supply chain compromise

Pen Test Partners: Hacking, tracking, stealing and sinking ships

gCaptain: Anthropic says Iran-linked actor used Claude to compile US Navy targeting data

SAFETY4SEA: USCG maritime cyber incidents rise 17%

Maritime Executive: Maritime cyberattacks doubled in 2025 (Cytur)

Rules and guidance

IMO: MSC-FAL.1/Circ.3/Rev.3 Guidelines on maritime cyber risk management

IUMI: Update on MSC 110

ClassNK: MSC 111 summary

IACS: UR E26 and E27 press release

Maritime Executive: New Coast Guard cyber rules take hold

Hill Dickinson: Global maritime industry continues to address cyber risk

MARAD: U.S. Maritime Advisory 2026-008

made using Leaflet