Coast Guard and FBI Boarded a VLCC Off Texas Over a Cyberattack
Two US-bound tankers reported compromised networks; suspicion has settled on Iran

A specialist Coast Guard team and the FBI boarded a very large crude carrier on arrival off Texas after indications that the ship's networks had been compromised by foreign actors. The investigation covers at least two United States-bound tankers whose crews reported incidents last month.
The ship is the tanker VL Prosperity (IMO 9683697), a 319,547 dwt Liberian-flagged VLCC managed by HMM Ocean Services and bound for Galveston. The boarding party combined Coast Guard law-enforcement personnel, a vessel inspector and members of a Coast Guard Cyber Protection Team with the FBI's Cyber Action Team. The first inspection took place on 21 August and was followed by a second on 24 August. The tanker has remained at anchor off Galveston since.
In a joint statement the two agencies said the investigations "were designed to ensure the integrity of the vessel's operational and information technology systems following indications that the networks of both vessels were compromised by foreign actors" and that there were "no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts". A second ship, reported to be an LNG carrier, has not been named.
Suspicion has settled on Iran, for the ordinary reason that Iranian state-aligned news agencies were describing the incident before anyone else was. On 20 August one of them ran a claim that the VL Prosperity had been hit by a major cyberattack in the Strait of Gibraltar and that all her communications were cut for 30 hours. The same report, attributed to a crew member, claimed that attackers had reached the engine-room systems, cut the engine cooling flow, increased engine speed and disabled the fuel and lubricating oil tanks. A follow-up piece carried the headline "No American Vessel is Safe Anymore: Will Cannons Give Way to Codes?".
None of that has been corroborated, and the specific technical claims are the part to treat carefully: a hull that reached Texas under her own power and is sitting quietly at anchor is not consistent with an engine that was run up with its cooling cut. What the claim establishes is intent and attribution theatre, not effect. The Coast Guard has said nothing about what was actually found aboard.
The distinction that matters for owners is between the information systems and the operational ones. Compromising a ship's business network — mail, cargo documents, crew laptops — is common and largely a commercial nuisance. Reaching the engine control, ballast or steering systems is a different class of event, and it is the one class regulators have never had to handle in a casualty inquiry. Class societies and security analysts have warned about it since integrated bridges became standard, and GPS jamming and spoofing have already been cited by at least one tanker as a contributing factor in a grounding in the Red Sea.
The regulatory floor is nine years old. The IMO issued its first guidance on maritime cyber risk management in safety management systems in June 2017, treating information loss or corruption as a safety and security failure to be handled through the ISM system. The instrument assumes a shipowner defending its own systems. It was not written for a state actor selecting hulls by flag and destination.
This story is part of the Maritime Briefing of 20 September 2026.
Ships in this story


