It was reported this week that United States Coast Guard personnel, joined by agents of the FBI, boarded a Texas-bound commercial oil tanker in the Atlantic Ocean last month after a foreign actor compromised the vessel’s computer network. Iranian state media has since claimed hackers gained control of the vessel’s propulsion, navigation, and cargo systems, and that the vessel also lost communications for 30 hours.
Although the U.S. Coast Guard didn’t disclose the supertanker’s name, Iranian reports identified it as the VL Prosperity, which is Liberian-flagged and bound for the port of Galveston. The vessel is capable of transporting 2.3 million barrels of oil.
South Korea-based HMM Ocean Service Co., Ltd., which manages the VL Prosperity, confirmed the Coast Guard had boarded the vessel, CBS News confirmed.
A Nautical Cyberattack
Specialized teams boarded the vessel in the Gulf of Mexico and worked with crews to remove potential threats to its network systems. The VL Prosperity was reportedly attacked while transiting the Strait of Gibraltar in early August and lost communications for more than 30 hours. A second tanker that was targeted in a separate cyberattack was boarded on August 24 for a similar assessment.
The U.S. Coast Guard and FBI said there have been no reported operational disruptions, vessel instability, physical danger to crews, or environmental impacts. However, experts warn the situation could have been worse.
A physical takeover of a supertanker could be difficult to weaponize, but the nature of hijacking has expanded into the digital space, as modern supertankers rely heavily on automated and connected systems.
Cybersecurity investigations have highlighted instances in which foreign actors or hackers successfully compromised a tanker’s networks, temporarily gaining control of its propulsion, navigation, and cargo systems. Such a digital hijacking is a modern variation of this threat, as it could enable bad actors to disrupt global supply chains or alter a vessel’s course remotely without ever setting foot on the ship.
Supertankers are just the newest threat vector.
“There’s a lot of conversation right now about attacks against operational technology, especially water and power systems, given the current geopolitical climate. But tankers are absolutely on the menu as well,” warned John Strand, owner of Black Hills Information Security, Inc.
“What makes these environments so attractive is that much of this technology doesn’t have the same endpoint security you would expect on a Windows 11 workstation,” Strand told ClearanceJobs via an email. “You often don’t have EDR running on these systems. That creates a rich target for attackers because many of the defensive technologies we’ve come to rely on in traditional IT aren’t there.”
How Serious Was The Attack?
Details of the cyberattacks on the two supertankers are still coming into focus. Still, Dahvid Schloss, OSCP and chief operating officer at Suzu Labs, told ClearanceJobs that the threat to the vessels shouldn’t be downplayed, but it may not be as serious as Tehran claims.
“It appears two separate claims are circulating, and they’re being treated as one. The first one is from the Coast Guard, which has acknowledged indications that the vessel’s network was compromised, with no reported operational disruptions,” Schloss explained.
He noted that the other report came from Iranian media and cited a single unnamed crew member, who alleged a much more extensive compromise involving cooling, fuel systems, and other critical elements of the vessel. It should be noted, too, that Tehran has claimed to have shot down a Lockheed Martin F-35 Lightning II and, two years ago, reported the Houthi claims of seriously damaging a U.S. Navy aircraft carrier in the region.
The extent of the attacks on the ships has yet to be independently verified.
“It’s important to keep your skeptical hat on,” Schloss continued. “Additionally, it’s important to note that Iranian media reporting on the incident also does not establish Iranian responsibility; attribution remains unresolved.”
Still a Serious Threat
The fact that two ships were hacked suggests that greater efforts are needed to ensure that the networks of all vessels are hardened against such attacks. A cyberattack on a tanker at sea could still disrupt commercial shipping, especially in key chokepoints, even if the risk of a compromised aircraft being flown into a building is lower.
“Physical maritime operations and global energy supply chains face severe operational risks when shipboard networks are compromised,” Damon Small, a board member at cybersecurity provider Xcape Inc., suggested.
“Contrary to official statements downplaying the event, a 30-hour communications blackout on a crude carrier is a significant operational disruption,” Small told ClearanceJobs.
A major concern is that vessels underway depend heavily on continuous communications for navigation and collision avoidance, meaning an unannounced blackout can easily precipitate a maritime disaster.
“Modern commercial watercraft rely on multi-channel connectivity including Very Small Aperture Terminal (VSAT), cellular, and Wi-Fi systems, making a sustained blackout indicative of critical bridge system failure,” added Small. “Defenders must strictly segment bridge communication links from physical operational technology domains, audit firmware across satellite hardware, and monitor for anomalous signal degradation.”
Communication loss can directly compromise vessel navigation, making a multi-hour blackout a primary operational threat rather than a minor IT glitch. The various systems – including VSAT, cellular, and Wi-Fi links – should have a strict degree of separation to prevent lateral movement into shipboard control systems.
“The reported communications outage raises a separate technical question. A compromise of the communications suite, or plain RF interference, could explain a 30-hour outage without a threat actor ever touching the ship’s controls,” Schloss noted. “GPS receivers and satellite terminals are chronically soft targets, and I spent enough of my military career working through degraded and jammed satellite comms to know how ordinary that failure mode is. The Strait of Gibraltar in particular is a well-documented GNSS interference corridor, so that’s a possibility I’d want investigators to rule in or out early. However, an outage on its own still tells you nothing about how far an intrusion actually reached.”
Small further emphasized that maritime operators should treat satellite communications and bridge telemetry as mission-critical assets requiring continuous anomaly monitoring.
“Calling a 30-hour communication blackout on a crude carrier non-disruptive is like ignoring a broken ship’s wheel because the horn still works,” Small continued.
Warnings Need to be Heeded
Even without serious compromise, the recent hacking of the ships’ systems could be seen as a portent of worse to come.
“No major disruption, environmental impact, or danger to the crew, and if a threat actor genuinely had control of propulsion on a fully loaded crude carrier, the obvious question is why nothing was done with it. When I’ve seen this pattern in the past, it usually points to a proof-of-concept or recon attack, more colloquially put, a rehearsal, not a performance,” Scholls acknowledged.
Was this a rehearsal for a larger attack, or something else, perhaps a ransomware attack in real time?
Scholls said he can’t say, but neither can anyone else right now, and that will remain something for the investigators to work out.
“Either way, with global oil supply already at its tightest it’s been in modern history, this isn’t a low-consequence practice run,” Scholls cautioned. “Regardless, this is a significant situation. A suspected compromise aboard a tanker warrants serious attention even if propulsion and other critical systems continued operating normally. The fact that the Coast Guard and FBI deployed their cyber teams to assess the vessel and remove potential threats shows the importance, even if it does not validate the more dramatic claims.”



