Full Breakdown
U.S. Coast Guard and FBI Board Oil Tankers Over Suspected Cyberattack
By Drooid · · How we work
Core Incident: Boarding of VL Prosperity and a Second Tanker
In late August 2026, U.S. Coast Guard law-enforcement personnel, vessel inspectors, members of the Coast Guard Cyber Protection Team, and FBI Cyber Action Team operators boarded two foreign-flagged tankers bound for the United States. The first boarding occurred on August 21 in the Gulf of Mexico aboard the Liberian-flagged very large crude carrier VL Prosperity (IMO 9683697), a 333-meter vessel capable of carrying roughly 2.3 million barrels of oil and managed by HMM Ocean Services. A second, as-yet-unnamed LNG carrier was boarded on August 24 under the same protocol to assess possible compromises of the ships’ operational-technology and information-technology networks.
Background & Context: Rising Maritime Cyber Threats
Maritime cyber risk has intensified as commercial vessels integrate advanced digital systems for navigation, propulsion, and cargo management. The International Maritime Organization issued its first Maritime Cyber Risk Management directive in June 2017, warning that malware, ransomware, and other intrusions could jeopardize safety and supply-chain continuity. U.S. authorities have increasingly targeted “dark fleets” that transport sanctioned oil from Iran and Russia, which rely on digital masking and present heightened cyber vulnerabilities.
Timeline of Events
- Early August 2026 – Iranian state media reported that VL Prosperity lost communications for about 30 hours after a cyber incident in the Strait of Gibraltar.
- August 21 2026 – Coast Guard and FBI boarding team inspected VL Prosperity in the Gulf of Mexico.
- August 24 2026 – A similar boarding team inspected a second, unnamed LNG carrier.
- September 15 2026 – The Coast Guard publicly confirmed the boardings and provided an update on the investigation.
Data & Statistics
- VL Prosperity: 333 m length, 319,547 dwt, capacity ? 2.3 million barrels of crude oil.
- Communication outage: loss of ship-to-shore communications for roughly 30 hours.
- Crew cooperation: captains, crew, and shore-based staff on both vessels assisted investigators.
- Operational impact: No reports of vessel instability, crew injury, or environmental harm.
Official Statements & Responses
Iranian media claimed attackers penetrated engine-room systems, reduced cooling flow, increased engine speed, and interfered with fuel and lubricating-oil systems, but U.S. officials have not attributed the breach to a specific actor.
Criticism & Opposition
Former President Donald Trump rejected the notion that Iran was responsible for the maritime cyber incidents, countering speculation that the attacks were part of Tehran’s broader campaign against U.S. interests. Senior officials from the previous administration declined to answer reporters’ questions about Iranian cyber activity, indicating a reluctance to confirm attribution without conclusive evidence.
Conflicting Reports & Gaps
U.S. agencies confirm a network compromise but have not disclosed technical details or identified the responsible party. Iranian state media allege direct control over propulsion, navigation, and cargo systems, but these claims remain unverified by independent analysis. The identity and cargo of the second boarded LNG carrier have not been disclosed, leaving a gap in public understanding of the full scope of the incidents.
What’s Next
U.S. authorities continue to investigate, coordinating with port operators and vessel owners to monitor for delayed effects. Ongoing surveillance of maritime networks and further boardings may occur if additional indications of compromise emerge.
