Last month, two oil tankers headed to Texas became the focus of a coordinated response by the US Coast Guard and FBI following cyberattacks that disrupted their journeys, as reported by CBS News citing US officials. These incidents highlight the growing threat of cyberattacks within the maritime industry.
Details of the Cyberattacks
The VL Prosperity, a Liberian-flagged crude tanker, departed from Egypt on August 1, destined for Galveston, Texas, according to vessel-tracking data referenced by CBS News. Allegedly, the cyberattack occurred on August 7 when the tanker was in the Strait of Gibraltar, as reported by Iran’s Mehr News Agency. The intrusion reportedly affected the engine room, manipulating coolant flow, engine speed, and fuel delivery.
The attackers allegedly gained access to the navigation and cargo systems, also cutting off communications for about 30 hours. Following these reports, a specialized team, including Coast Guard cyber experts and FBI Cyber Action Team members, boarded the VL Prosperity, conducting a four-day investigation.
Investigations and Security Measures
The Wall Street Journal noted a second tanker was boarded on August 24, with both vessels reaching the Gulf of Mexico before being investigated. The US Coast Guard has not officially linked these incidents to any specific nation, including Iran. However, Rear Adm. Amy Grable, leading the Coast Guard Cyber Command, confirmed that evidence of malicious cyber activity was discovered upon reviewing the vessels’ IT systems.
Quinton DuBose, a former Coast Guard cyber official, expressed skepticism about the possibility of hackers fully controlling a supertanker. Instead, he suggested that the risk lies in attackers compromising enough systems to hinder safe operation. The investigation is ongoing to determine any connections between the incidents and potential state actors.
Maritime Cybersecurity Concerns
These events underscore the vulnerabilities of the maritime sector, which relies heavily on outdated operational technology systems. The US Coast Guard has recently launched an Office of Maritime Cybersecurity Policy to address these challenges by creating and enforcing cybersecurity standards for marine transportation.
Cybersecurity professionals have long warned about the maritime industry’s exposure to cyber threats due to reliance on aging systems, satellite communications, and IoT devices. Successful breaches can lead to severe consequences like GPS spoofing or navigation system manipulation, threatening global shipping operations.
As 80% of worldwide goods are transported by sea, a significant cyberattack could result in substantial financial losses and disrupt supply chains. The recent incidents serve as a critical reminder of the importance of bolstering cybersecurity defenses in the maritime sector.
