A HACKED TANKER CAN THREATEN A PORT

TODAY’S DISRUPTIVE BLOG

Maritime cybersecurity is now a safety and continuity obligation.

Dennis G. Perry, PhD, MBA  |  September 19, 2026

Figure 1. A cyber incident aboard a connected vessel can create safety, environmental, and port-continuity consequences.

Introduction

U.S. Coast Guard cybersecurity personnel and FBI agents boarded two U.S.-bound energy tankers after indications that both vessels’ networks had been compromised. One was the VL Prosperity, a 1,093-foot crude-oil tanker capable of carrying roughly 2.3 million barrels. Investigators found malicious cyber activity aboard the vessels [1], [2].

That is the established story. U.S. authorities have not publicly confirmed the more dramatic claim that hackers seized propulsion, navigation, cargo, cooling, fuel, and lubrication functions. Iranian reporting alleged interference with engine speed, cooling flow, fuel systems, and communications, but attribution and the extent of operational access remain unresolved [2].

The uncertainty is not a reason to dismiss the event. It is a reason to describe it accurately. A cyberattack does not need cinematic remote control of an entire tanker to create danger. Disrupting communications or one critical subsystem at the wrong time could complicate safe navigation, delay cargo movements, increase environmental risk, or disrupt a port.

What Is Confirmed

The Coast Guard and FBI boarded the vessels in the Gulf of Mexico between August 21 and August 24 to assess the integrity of operational and information technology systems. The agencies reported no operational disruption, vessel instability, danger to the crew, or environmental impact [1]. Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, later confirmed that investigators found malicious cyber activity, while stating that the vessel was not found unsafe to navigate when the response team boarded [2].

That distinction matters. Public evidence supports a real cyber compromise and a significant federal response. It does not yet support declaring that an adversary remotely hijacked a supertanker. Inflating the evidence would weaken the warning. The confirmed facts are already serious enough.

A Vessel Incident Can Become a Port Incident

A modern tanker depends on interconnected business, communications, navigation, engineering, cargo, and support systems. Those systems are not identical across the fleet, and public reporting does not establish the precise architecture involved in these incidents. But the general risk is clear: a vessel cyber incident can affect more than data.

A loss of reliable communications can complicate coordination. A disruption to navigation or machinery support can delay safe movement. Loss of availability at the wrong point in an approach or departure can affect pilots, tugs, terminals, other vessels, and traffic management. A disabled or uncertain vessel can restrict a channel even without a collision or spill.

The relevant unit of risk is therefore not merely the ship. It is the ship, its crew, its cargo, the waterway, the receiving terminal, and the surrounding port economy.

The Weakest Link May Be Ordinary

The maritime sector should resist the comforting assumption that an incident of this scale must require an exotic zero-day. Publicly discussed weaknesses across maritime and industrial environments include exposed remote access, poor credential practices, phishing, incomplete asset inventories, obsolete software, weak segmentation, insecure vendor connections, and inconsistent monitoring.

The Coast Guard has emphasized segmentation, phishing resistance, and basic cyber hygiene. NIST guidance likewise treats asset visibility, boundary protection, controlled remote access, monitoring, incident response, and recovery planning as essential elements of operational technology security [2], [4]. These measures are not glamorous. They are still where many failures begin.

Five Questions Every Vessel Operator Should Answer

Executives and vessel operators do not need to wait for final attribution before acting. They should be able to answer five basic questions with evidence:

  • Which onboard systems can communicate with external, shoreside, crew, or vendor networks?
  • Which remote-access pathways exist, who owns them, and when were they last reviewed?
  • Can the crew continue safe operations when digital communications or supporting systems are unavailable?
  • How quickly would the organization detect unusual access, degraded integrity, or loss of availability?
  • Do cyber exercises include bridge, engineering, cargo, safety, environmental, legal, and port-response personnel?

If the answers depend on diagrams no one has updated, accounts no one owns, vendors no one monitors, or recovery procedures no one has tested, the organization lacks a cybersecurity program. It has assumptions.

Cybersecurity Must Join the Safety System

Maritime cybersecurity cannot remain isolated inside the information technology department. A vessel already manages navigation safety, machinery reliability, hazardous cargo, pollution prevention, emergency response, and human factors. Cyber risk now affects each of those disciplines.

That means cyber events should be incorporated into safety management, drills, watchstanding procedures, contingency planning, vendor governance, maintenance, and incident command. Manual fallback must be both technically possible and operationally practiced. A procedure that exists only in a binder is not a recovery capability.

The goal is not to make every vessel immune to intrusion. That is unrealistic. The goal is to prevent a digital compromise from escalating unchecked into an unsafe operating condition and to preserve the crew’s ability to understand, contain, and recover from the event.

The Regulatory Clock Is Running

The Coast Guard’s Cybersecurity in the Marine Transportation System rule became effective July 16, 2025. It establishes baseline cybersecurity requirements for covered U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities regulated under the Maritime Transportation Security Act [5]. The implementation schedule requires major cybersecurity officer, assessment, and plan obligations by July 16, 2027 [6].

Internationally, the IMO’s revised Guidelines on Maritime Cyber Risk Management call for addressing cyber risk through governance, identification, protection, detection, response, and recovery, while recognizing dependencies between information and operational technology [3].

The mistake would be treating these requirements as a documentation exercise. A polished plan cannot compensate for an unknown remote-access path, an untested manual procedure, or a crew that has never practiced operating through a cyber disruption.

The Hard Truth

Maritime transportation was engineered around physical hazards, mechanical failure, weather, and human error. It must now operate in an environment where an adversary may deliberately create confusing or contradictory technical conditions.

That changes the standard for resilience. Operators must assume that trusted credentials can be stolen, approved vendors can be compromised, telemetry can become unreliable, and communications can disappear. The response must integrate cyber defense with operational judgment rather than forcing the crew to choose between them during an emergency.

The Upshot

The VL Prosperity incident is not yet proof of a remotely hijacked supertanker. It is proof that malicious cyber activity reached systems aboard U.S.-bound vessels and triggered an extraordinary federal response.

The maritime industry should treat that as a warning before a cyber incident coincides with constrained waters, hazardous cargo, poor visibility, equipment failure, or a busy port approach.

The next maritime cyber crisis may begin on a computer. Its consequences will not remain there.

References

[1] Z. Whittaker, “FBI, Coast Guard boarded hacked oil tankers heading toward US coast,” TechCrunch, Sept. 18, 2026. https://techcrunch.com/2026/09/18/fbi-coast-guard-boarded-hacked-oil-tankers-heading-towards-us-coast/

[2] N. Sganga, “Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?” CBS News, updated Sept. 16, 2026. https://www.cbsnews.com/news/coast-guard-fbi-boarded-energy-tankers-cyberattacks-amy-grable-iran/

[3] International Maritime Organization, Guidelines on Maritime Cyber Risk Management, MSC-FAL.1/Circ.3/Rev.3, Apr. 4, 2025. https://wwwcdn.imo.org/localresources/en/OurWork/Facilitation/Facilitation/MSC-FAL.1-Circ.3-Rev.3.pdf

[4] K. Stouffer et al., Guide to Operational Technology Security, NIST SP 800-82 Rev. 3, Sept. 2023. https://doi.org/10.6028/NIST.SP.800-82r3

[5] U.S. Coast Guard, “Final Rule: Cybersecurity in the Marine Transportation System,” July 16, 2025. https://www.news.uscg.mil/maritime-commons/Article/4033732/final-rule-cybersecurity-in-the-marine-transportation-system/

[6] U.S. Coast Guard, “Final Rule: Cybersecurity in the Marine Transportation System – Implementation Timeline,” 2025. https://www.news.uscg.mil/maritime-commons/Article/4247529/final-rule-cybersecurity-in-the-marine-transportation-system-implementation-tim/

Hashtags

#MaritimeCybersecurity  #OperationalTechnology  #CriticalInfrastructure  #MaritimeSecurity  #PortSecurity  #CyberResilience  #IndustrialControlSystems  #SafetyManagement  #IncidentResponse  #SecureEnergy

Leave a Reply

Discover more from Disruption is a Fact of Life

Subscribe now to keep reading and get access to the full archive.

Continue reading