WHAT YOU NEED TO KNOW
- Coast Guard personnel and FBI agents boarded VL Prosperity after indications that its network might have been compromised by a foreign actor.
- Iranian state media claimed hackers controlled propulsion, navigation and cargo systems, while the tanker reportedly lost communications for 30 hours.
- Investigators examined operational and information technology systems and worked with the crew and corporate operators to remove the potential threat.
- The Coast Guard reported no operational disruptions, vessel instability, danger to crews or environmental impacts.
Coast Guard personnel and FBI agents boarded a commercial oil tanker traveling toward Texas after officials found signs that its network might have been compromised by a foreign actor.
The boarding took place in the Atlantic last month, the Coast Guard said Tuesday.
Iranian state media offered a more dramatic account, claiming hackers obtained control over the tanker’s propulsion, navigation and cargo systems. Those reports also said the ship lost communications for 30 hours.
The Coast Guard did not disclose the vessel’s name. Iranian reports identified it as VL Prosperity, a massive 333 meter supertanker capable of carrying roughly 2.3 million barrels of oil.
Public vessel data showed that the Liberian flagged very large crude carrier was bound for Galveston, Texas.
HMM Ocean Service Co., Ltd., the company based in South Korea that manages VL Prosperity, confirmed that the Coast Guard had boarded the ship.
Iran’s Mehr News Agency reported on Aug. 20 that VL Prosperity had been attacked while traveling toward the United States from Egypt’s Sidi Kerir terminal. The report said the ship lost communications on Aug. 7.
Citing an unnamed crew member, Mehr alleged that the attackers penetrated systems in the engine room. The report claimed they reduced engine cooling flow, increased engine speed and interfered with fuel and lubricating oil systems.
According to the Coast Guard, the team boarded the ship on Aug. 21. It included specialized Coast Guard law enforcement personnel, a vessel inspector, members of the Coast Guard Cyber Protection Team and operators from the FBI Cyber Action Team.
Investigators examined the tanker’s operational technology and information technology systems. They also worked with the crew and the vessel’s corporate operators to remove the potential threat.
The Coast Guard reported no continuing operational consequences on Tuesday. It said there were currently “no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”
Unconfirmed accounts of the incident first appeared publicly after the tanker passed through the Strait of Gibraltar, between Spain and Morocco. The United States has released few details about the scope of the suspected breach.
Officials have confirmed only that there were indications the tanker’s network had been compromised. The United States has not publicly attributed the possible cyberattack to any specific actor.
The potential consequences of penetrating a commercial oil tanker’s systems extend beyond stolen information or disrupted communications.
Modern tankers use interconnected operational technology to control propulsion, navigation and cargo systems, all of which are connected to the internet.
Although such an outcome is considered unlikely, remote access by a hostile state could theoretically allow an attacker to manipulate a vessel’s movement or critical machinery. That possibility could turn a massive oil tanker into a threat against a port.
HMM emphasized its security procedures following confirmation that authorities had boarded the vessel.
The company stated that it “has rigorous cyber protocols in place to ensure the safety and security of vessels under our care.”
Iranian state media continued to promote the story during the weeks after the reported breach. Its coverage suggested that the regime was opening a new cyber front in the war with the United States.
Four days after Mehr published its report, Iran’s Tasnim News Agency escalated the message with a pointed headline. The article was titled “No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?”
Despite those claims, the available American account remains limited to indications of a possible network compromise and the subsequent inspection.
Authorities reported no operational disruption, instability, danger to the crew or environmental impact, while leaving the suspected attacker unidentified.
WATCH BELOW:
Join the Discussion
COMMENTS POLICY: We have no tolerance for messages of violence, racism, vulgarity, obscenity or other such discourteous behavior. Thank you for contributing to a respectful and useful online dialogue.