VYPR
breachPublished Oct 6, 2026· 1 source

US Coast Guard Boards Hacked Supertankers Exploiting Known Vulnerabilities

Two U.S.-bound supertankers were boarded by Coast Guard and FBI cyber specialists in August after cyberattacks exploited known, unpatched vulnerabilities in their on-board systems, a federal official revealed.

Two U.S.-bound supertankers were subjected to cyberattacks in August, leading to boardings by Coast Guard and FBI cyber specialists. A federal official disclosed that these attacks exploited known, unpatched vulnerabilities within the vessels' on-board systems, emphasizing that the incidents were preventable.

The joint offshore security boardings occurred in the Gulf of Mexico on August 21 and August 24. The FBI and Coast Guard stated the operations were designed to ensure the integrity of the vessels' operational and information technology systems following indications of network compromise. While initial reports focused on potential Iranian involvement, no official attribution has been made.

This revelation adds a critical detail to the previously reported incidents: the exploitation of vulnerabilities that were already identified and unaddressed. This highlights a significant gap in maritime cybersecurity, where known weaknesses in critical infrastructure systems are being leveraged by attackers.

Retired Rear Adm. John Mauger, formerly of the Coast Guard, noted that such boardings, especially those initiated by cyber concerns, are unusual. Typically, Captain of the Port orders, which authorize these boardings, are issued for traditional maritime issues like navigational glitches or health concerns. The issuance of two cyber-based orders in the same week underscores the growing threat and the Coast Guard's developing cyber capabilities.

Adm. Amy Grady, head of Coast Guard Cyber Command, confirmed that Cyber Protection Teams detected "malicious cyber activity" in the on-board systems of both vessels. The Coast Guard emphasized its commitment to anonymity for reporting cyber incidents, aiming to build trust with vessel owners and operators, many of whom are legitimate companies concerned about reputational damage.

Further analysis by Dragos identified the vessels as the crude oil supertanker VL Prosperity and the liquefied petroleum gas supertanker Kohaku. Reports also surfaced of a cyberattack on the liquefied natural gas supertanker Vivit Africa LNG while en route to Italy, with all three incidents occurring near the Straits of Gibraltar, suggesting a potential pattern.

Experts like Liz Martin from Dragos highlighted the blurred lines between Operational Technology (OT) and Information Technology (IT) systems on modern vessels. This convergence means that an IT intrusion can easily lead to OT access, potentially enabling the weaponization of these large vessels, which carry significant amounts of oil, with far-reaching downstream impacts.

The incidents underscore the urgent need for robust patch management and vulnerability remediation in the maritime sector. The reliance on known, unpatched vulnerabilities by attackers presents a clear and present danger to critical infrastructure and global supply chains.

Synthesized by Vypr AI