Threat intel
Hackers reached a US-bound supertanker's propulsion
FBI and Coast Guard found hackers had accessed the VL Prosperity's propulsion system. What is confirmed, what is only claimed, and what ship and OT teams should check.
On October 2, Bloomberg reported that FBI and US Coast Guard investigators found evidence that hackers had accessed the propulsion system of the VL Prosperity, a 1,093-foot (333-metre) Liberian-flagged crude carrier able to hold about 2.3 million barrels, as it approached Texas this summer. It had left Egypt's Sidi Kerir terminal on August 1 bound for Galveston. Investigators describe temporary access to its digital systems; how the attackers got in, who they are, how long they stayed and what they could control are all unconfirmed.
This intrusion reached the operational technology (OT) that runs a ship's engines, steering and pumps. The weakness described in the reporting, an internet link with one firewall in front of a shared network, is just as common in plants, pipelines and buildings. Anyone whose OT is reached through a single gateway or a vendor's remote access tool can check the same weak points this week.
Confirmed findings and unconfirmed claims
What US officials say. On August 21 a joint team boarded the ship and spent four days aboard. In its statement the Coast Guard said the boarding followed "indications that the vessel's network were compromised by foreign cyber actors." The team included a Coast Guard Cyber Protection Team, a vessel inspector and the FBI Cyber Action Team. Rear Admiral Amy Grable, who commands Coast Guard Cyber Command, told CBS News investigators "did find malicious cyber activity" in the ship's IT and onboard systems, and that nothing suggested the vessel was unsafe. A second foreign-flagged, Texas-bound vessel was boarded on August 24 in the Gulf of Mexico; its name has not been released. The FBI said there were "no reports of operational disruptions, vessel instability, physical danger to crews or environmental impacts." Reports disagree on where the first boarding took place: some say the Atlantic, others the Gulf of Mexico.
What Iranian state media claims. On August 20, before any US acknowledgement, Iran's Mehr News Agency named the ship. It said the attack happened on August 7 in the Strait of Gibraltar, that hackers reached propulsion, navigation and cargo systems, and that communications were down for about 30 hours. Citing one unnamed crew member, Mehr said the intruders cut engine cooling flow, raised engine speed and interfered with fuel delivery. No US agency has confirmed the date, the location, the 30 hours or any of those engine changes, and none has attributed the attack to Iran or anyone else. Quinton DuBose, a former Coast Guard cyber official, told CBS News that attribution "can take weeks or months."
By mid-September, Bloomberg reported, US agencies were tracking cyber threats against nearly 20 ships worldwide, and the Coast Guard had asked for advance notice before any of them enters a US port.
How a ship's network gets from the internet to the engine room
A modern tanker carries two kinds of systems. The IT side covers email, crew internet, and cargo and voyage planning software. The OT side covers the bridge (radar, the electronic chart display and information system or ECDIS, autopilot) and the engine room, where an alarm monitoring and control system watches temperatures, pressures and flows, and the propulsion control system sets engine speed and pitch.
Both sides need data from shore. Charts update over the satellite link, engine makers pull performance data for maintenance, and vendors connect remotely to troubleshoot. CBS News reported that on many ships the barrier between the satellite internet connection and those critical systems can be a single firewall. Robert M. Lee, CEO of the OT security firm Dragos, described what often sits behind it as "navigation, propulsion, ballast, steering, ship command, everything on one shared network." Grable's stated concern in this case was IT systems being connected to the systems that control propulsion and navigation.
A foothold on any machine on the IT side, from a phishing email, a stolen remote access login or an exposed satellite terminal admin page, becomes a foothold on the engine network if the firewall rules allow traffic between the two or if both sit on one flat network. Once there, engine and alarm controllers usually speak industrial protocols with little or no authentication, so anything that can reach them can often change setpoints, the target values such as speed or temperature that a controller holds.
Investigators have not said which of these paths was used here. Grable pointed operators at network segmentation, phishing and basic cyber hygiene: "Just taking basic precautions would prevent most of these occurrences." The boarding was one of roughly 40 to 50 missions her Cyber Protection Team has carried out in the past year.
What to do
These steps are written for ship operators and managers but apply to any site where OT is reached through one internet gateway.
1. Map every path into OT. List each connection that can reach bridge or engine systems: every satellite terminal (VSAT, Starlink or L-band), 4G or 5G routers used in port, vendor remote access appliances and any laptop that plugs into both networks. Ask each equipment maker in writing how they connect and from where.
2. Separate IT from OT at the firewall. Put bridge and engine systems in their own zone with a default deny rule both ways. Allow only named flows, such as chart updates from one internal server to the ECDIS. Export the current rule set and look for any rule with any as source or destination that touches the OT zone.
3. Control remote access. Remote vendor sessions should be off by default, switched on for a set window by the crew or the shore office, require multifactor authentication (MFA) and be logged. Remove standing tools such as TeamViewer or AnyDesk from engine control and alarm workstations, and change default passwords on satellite terminal management pages.
4. Check whether you were already hit. Pull firewall logs from the satellite gateway and look for connections from the OT zone to the internet, or inbound sessions to OT from addresses you do not recognise. On engine and bridge workstations, list installed software and scheduled tasks for remote access tools nobody approved. In the alarm monitoring system, review the event history for setpoint or mode changes nobody on watch made. Compare controller configuration against the last known-good backup.
5. Practise losing the network. Make sure engineers can take local control of the main engine and steering, and that the crew has rehearsed it. Keep offline copies of controller configurations so a system can be rebuilt without the vendor's remote session.
6. Report it. US-flagged vessels and facilities covered by the Maritime Transportation Security Act (MTSA) must report reportable cyber incidents to the National Response Center under the Coast Guard's cybersecurity rule, in force since July 16, 2025. That rule requires training by January 12, 2026 and an approved cybersecurity plan by July 16, 2027. Foreign-flagged ships like the VL Prosperity fall under the International Maritime Organization's (IMO) requirement, resolution MSC.428(98), to cover cyber risk in their safety management system. Ships contracted for construction on or after July 1, 2024 must also meet the classification societies' cyber resilience rules, IACS UR E26 and E27.
The same checks on land
A plant whose historian (the server that logs process data) shares a subnet with its controllers, or whose integrator keeps an always-on remote access tool, has the same exposure as the ship. Run steps 1 to 4 against that gateway. Our post on Iran-linked attacks on exposed PLCs covers controllers that answer directly from the internet.
Our network penetration tests check whether someone on your business network can reach your control systems, and our safeguarding and hardening work tightens the firewall rules and remote access in between. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Bloomberg: hackers breached propulsion system of US-bound oil tanker, SupplyChainBrain (Bloomberg), Transport Topics (Bloomberg), Bloomberg: US tracking cyber threats against nearly 20 ships, CBS News, The Record, SecurityWeek, SAFETY4SEA, Holland & Knight, US Coast Guard: final rule on cybersecurity in the Marine Transportation System, Blank Rome: the Coast Guard's final rule, ClassNK: IACS UR E26/E27, Pen Test Partners: IACS UR E26 and E27 guidance.