AI News Feed
Market watch
Cybersecurity

FBI and Coast Guard Board U.S.-Bound Tankers After Suspected Cyber Intrusions

The FBI and U.S. Coast Guard boarded U.S.-bound tankers in the Gulf of Mexico after suspected foreign cyber compromise. One vessel, VL Prosperity, reported engine, fuel and communications disruptions; Iran is under investigation.

The Coast Guard released photos of its personnel and FBI agents climbing aboard one vessel, images shared with CBS News. The joint statement said the captain, crew and the on-shore staff of the vessel's owner cooperated with the agencies. A Coast Guard spokesperson did not immediately respond to TechCrunch's request for comment, including a request for the names of the vessels involved.

CBS News confirmed that one tanker was VL Prosperity, a 333-meter oil tanker capable of holding more than 2 million barrels of oil. VesselFinder listed the ship in the Gulf of Mexico. TechRadar, citing Cybernews, reported that VL Prosperity is a Liberian crude oil tanker carrying 2.3 million barrels and traveling from Egypt's Sidi Kerir Oil Terminal to Galveston, Texas, where it was due on Aug. 24. The roughly 25-day route passed through the Strait of Gibraltar, and the vessel requested assistance from law enforcement about three days before arrival. A Coast Guard spokesperson told Cybernews that a specialized team boarded the vessel on Aug. 21, including Coast Guard law enforcement personnel, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators.

Accounts of the intrusion differed in detail. CBS News, citing Iranian media, said hackers compromised the ship on Aug. 7 while it was traveling from Egypt to the United States and interfered with its speed and fuel systems; the tanker lost communications for more than a day. TechRadar said the Iranian Mehr News Agency reported that attackers infiltrated engine-room systems, reduced the engine's cooling flow, increased engine speed and disabled the ship's fuel and engine-oil tank, citing an unnamed crew member. Communications were offline for a day and a half, according to that account.

The second vessel was Kohaku, which flies the flag of the Marshall Islands, according to TechRadar. The Wall Street Journal reported that it was traveling toward Texas to load liquefied petroleum gas, and it had been near Malta before moving through the East Mediterranean Sea. TechRadar said the Kohaku was also affected, but it did not specify whether the Coast Guard and FBI boarded that ship. The joint statement shared with TechCrunch said agencies boarded the vessels, while TechRadar reported that a specialized team boarded at least one vessel. No threat actors had publicly claimed responsibility for the attacks.

Iranian media coverage hinted at possible Iranian involvement. TechRadar said the Mehr News Agency suggested the attack was a message from Iran's Resistance Front to Washington and the broader Middle East. CBS News said the United States was looking into whether Iran was behind the hack. TechCrunch reported that Iran has been behind numerous hacks in recent months after the start of the U.S. and Israel-led war against Tehran, which killed Iran's supreme leader in February. Iranian-backed hackers have since launched a destructive hack at medical device maker Stryker, hacked the mass transit system in Los Angeles and compromised more than 100 water facilities across the United States, according to TechCrunch. CISA has described the attacks as opportunistic in nature.

The Coast Guard later described the incident as malicious cyber activity, according to TechRadar. The joint FBI-Coast Guard statement said there were no reports of operational disruptions, vessel instability, physical danger to crews or environmental impacts.