BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 16, 2026 · 3 min read · Original story

Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’

Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’

The U.S. Coast Guard said it boarded a tanker transiting the Gulf of Mexico in August after the vessel’s network was attacked by hackers.

A Coast Guard spokesperson confirmed the incident after the Wall Street Journal reported that at least two tankers headed for the U.S. were hit with cyberattacks. Bloomberg News identified one of the tankers as VL Prosperity, and Iranian government-backed news outlet Mehr said the ship lost communications for 30 hours.

The FBI did not respond to requests for comment and several other agencies directed Recorded Future News to the U.S. Coast Guard, which said officials boarded the ship to “ensure integrity of the vessel’s operational and information technology systems following indications that the vessel’s network were compromised by foreign cyber actors.”

“On August 21, a highly specialized team — comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators — embarked the vessel to conduct a comprehensive cyber security boarding and investigation,” the spokesperson said.

“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”

The U.S. Coast Guard did not respond to questions about the nature of the attack, who was potentially behind it or whether the August 21 boarding involved VL Prosperity. The Wall Street Journal said another ship was boarded on August 24.

Mehr reported that VL Prosperity was flying under a Liberian flag from a port in Egypt headed to a port in the United States when it was attacked on August 7 while transiting the Strait of Gibraltar. A crew member told Mehr that the attackers were allegedly able to increase the engine speed and disable the ship’s fuel and engine-oil tank.

The news outlet cited Russian analysts who claimed the incident was connected to the current military conflict between the U.S. and Iran but no hacking group has taken credit for the incident. Bloomberg reported that VL Prosperity is currently located off the coast of Texas.

The U.S. Coast Guard spokesperson said it is still working with port operators, vessel owners, and local maritime stakeholders to “ensure port operations continue safely and without interruption.”

One day before the alleged attack on VL Prosperity, North Carolina Ports reported a cyberattack that forced a shift to manual operations.

A spokesperson for North Carolina Ports said at the time that its IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard.

Ports in the U.S., Europe and Asia have been repeatedly targeted by ransomware gangs over the last five years as many shift to incorporate digital operations. In 2024, the Port of Seattle refused to pay a ransom to cybercriminals that caused issues at the city’s airport and seaport ahead of the Labor Day holiday.

Several ports in Europe as well as large shipping companies Royal Dirkzwager and DNV were hit with ransomware in 2023 while oil companies Oiltanking and Mabanaft declared force majeure after cyberattacks in 2022 and logistics and freight forwarding giant Expeditors International similarly announced a cyberattack that crippled some of its operating systems for months.

References in this story

  1. US-bound oil tanker targeted in cyberattack en.mehrnews.com TEHRAN, Aug. 20 (MNA) – A Liberian-flagged oil tanker bound for the United States was hit by a major cyberattack in the Strait of Gibraltar, with all of its communications disrupted for 30 hours.
  2. Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate therecord.media North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.
  3. Ransomware attack disrupts operation at major Spanish fishing port therecord.media A ransomware attack has disrupted digital systems at Spain’s Port of Vigo, forcing authorities to disconnect parts of its network and temporarily manage cargo operations manually.
  4. Major Japanese port suspends operation following ransomware attack therecord.media A cybercrime group believed to be operating out of Russia hit the largest and busiest trading port in Japan with a ransomware attack.
  5. Seattle's airport, seaport isolate systems after cyberattack therecord.media The Port of Seattle, which oversees the Seattle-Tacoma airport, said there was no timetable for when certain systems would return to normal after an incident disrupted services over the weekend.
  6. Port of Lisbon website still down as LockBit gang claims cyberattack therecord.media The website for the Port of Lisbon is still down days after officials told a local news outlet that they were dealing with a cyberattack.
  7. Dutch shipping giant Royal Dirkzwager confirms Play ransomware attack therecord.media Dutch maritime logistics company Royal Dirkzwager has confirmed that it was hit with ransomware from the Play group, the latest in a string of attacks targeting the shipping industry.
  8. Ransomware attack on maritime software impacts 1,000 ships therecord.media About 1,000 vessels were affected by a ransomware attack affecting a major software supplier for ships and offshore structures
  9. Shell forced to reroute supplies after cyberattack on two German oil companies - ZDNET www.zdnet.com Two subsidiaries of German logistics firm Marquard & Bahls are struggling to respond to a cyberattack.
  10. Expeditors Targeted in Cyber-attack investor.expeditors.com SEATTLE--(BUSINESS WIRE)-- Expeditors International of Washington, Inc. (NASDAQ:EXPD) announced that on February 20, 2022, we determined that our company was the subject of a targeted cyber-attack. Upon discovering the…
  11. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  12. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  13. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  14. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news