US Authorities Board Foreign Tankers in Gulf of Mexico to Investigate Suspected Cyberattacks
The U.S. Coast Guard and FBI conducted joint offshore security boardings of two foreign tankers in the Gulf of Mexico to investigate suspected cyberattacks, following network compromises that disrupted communications.

In a significant move to bolster maritime cybersecurity, the U.S. Coast Guard and the FBI jointly boarded two foreign-flagged tankers in the Gulf of Mexico last month to investigate suspected cyberattacks. These "joint offshore security boardings," conducted on August 21 and August 24, were initiated after indications emerged that the operational and information technology networks of both vessels had been compromised.
The investigations aimed to ensure the integrity of the ships' systems following the network intrusions. While authorities reported no immediate signs of operational disruptions, vessel instability, physical danger to crews, or environmental impacts, the proactive boarding underscores the growing concern over cyber threats in the maritime sector. The Coast Guard has been actively coordinating with port operators, vessel owners, and local maritime stakeholders to ensure continued safe port operations.
One of the tankers, reportedly carrying oil and natural gas, experienced a significant communication outage lasting over 30 hours after an incident in the Strait of Gibraltar. This disruption, coupled with the broader network compromise, has prompted authorities to explore potential perpetrators. Early investigations are considering links to Iran or other state-sponsored or opportunistic groups seeking to exploit geopolitical tensions.
These actions are a direct consequence of enhanced authorities granted to the Coast Guard. An executive order signed in 2024 by President Joe Biden specifically cited the potential for "cascading" harm to the global supply chain from maritime cyber incidents, empowering the Coast Guard to address these emerging risks more effectively.
The boarding parties were comprehensive, comprising Coast Guard law enforcement personnel, members of the Coast Guard Cyber Protection Team, a vessel inspector, and FBI Cyber Action Team operators. Their mission was to conduct a thorough cybersecurity assessment and investigation, with the cooperation of the vessels' captains, crews, and shore-side corporate staff being crucial to mitigating the identified threats.
The "dark fleet" phenomenon, involving vessels used to transport sanctioned oil from Iran and Russia while employing digital masking techniques, has been a particular focus for the Coast Guard. These "dark fleets" are known to carry enhanced cyber risks due to their reliance on obfuscation, making them potential targets or conduits for cyberattacks.
While specific details regarding the technical nature of the compromises and the methods used by the attackers remain under investigation, the incident highlights the vulnerability of critical global supply chain infrastructure to cyber threats. The involvement of both the Coast Guard and the FBI signifies the seriousness with which these potential attacks are being treated.
The ongoing investigations seek to identify the actors behind these intrusions and understand their motives, whether they are state-sponsored espionage, disruption, or financially motivated cybercrime. The findings will likely inform future maritime cybersecurity strategies and enforcement actions.