Cyberwar doesn’t always look like ransomware pop-ups. Sometimes it looks like a 333-meter oil tanker with the wrong people on its network. On Friday, TechCrunch reported that cybersecurity teams from the U.S. Coast Guard and the FBI boarded two U.S.-bound oil tankers in the Gulf of Mexico between August 21 and 24 after indications both vessels’ networks were compromised.
A joint statement said the goal was to “ensure integrity of the vessel’s operational and information technology systems.” The captain, crew, and onshore owner staff cooperated. Officials released photos of agents climbing aboard. They did not name both ships in the statement—classic incident-response opacity while forensics still run.

VL Prosperity and a week of lost control
CBS News identified one tanker as VL Prosperity, a VLCC-class ship that can hold more than two million barrels. VesselFinder still showed it in the Gulf. Citing Iranian media, CBS reported the ship was compromised around August 7 on a run from Egypt to the U.S., with interference to speed and fuel systems and more than a day of lost communications.
TechCrunch’s framing of the boarding: hackers reportedly took control of navigation, propulsion, and cargo systems on at least one vessel. That is the nightmare slide for maritime OT—IT compromise bleeding into the systems that actually move steel and oil. Even a temporary loss of propulsion authority on a loaded VLCC is the kind of scenario that keeps port-state control and insurers awake.
Iran shadow, CISA “opportunistic,” no spill
Attribution remains murky. CBS said U.S. investigators are examining whether Iran is involved, against a backdrop of Iranian-linked hacks since the U.S.–Israel war that killed Iran’s supreme leader in February—Stryker, Los Angeles transit, and more than a hundred water facilities among the hits CISA has called opportunistic.
The joint FBI–Coast Guard line is careful: no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts. “No spill” is the best possible ending for a tanker cyber incident. It is also not the same as “no access.” Boarding after compromise is containment theater that worked this time; it is not a substitute for shipboard detection that pages someone before the Gulf of Mexico boarding party.
From water utilities to VLCCs
The same month’s broader Iran-linked campaign chatter—water facilities, transit, medtech—makes tanker OT feel less like a one-off CSI episode and more like a continuum. Ships are harder to patch at sea, slower to rotate crews through security training, and dependent on vendors who treat remote access as a feature. If your threat model stopped at ransomware locking the cargo spreadsheet, update it: propulsion and navigation sit on networks that still trust too many east-west paths.
Why tankers are juicy OT targets
Modern tankers run sprawling networks for navigation, cargo, and hotel systems across a floating industrial plant. Flat segments, vendor remote access, and satellite links give attackers paths that enterprise SOC playbooks still underweight. Boarding after the fact is incident response by helicopter. Prevention is segmenting OT, monitoring satcom, and treating propulsion PLCs like crown jewels—not afterthoughts behind the bridge Wi-Fi.
Global logistics already prices pirate risk and canal delays. Cyber control of course and cargo is a new line item insurers and charterers will start pricing louder. Expect more questions in charter parties about OT patch cadence, remote-access logging, and whether the ship’s integrator can still dial into the engine room from a coffee shop.
Geeknewz take
Two boarded tankers with intact hulls is a near-miss, not a nothingburger. If state-linked actors can touch nav and propulsion on a U.S.-bound VLCC, the next story isn’t a press photo of agents on a ladder—it’s a ship that doesn’t answer. Maritime operators: assume your OT is in scope. Everyone else: remember critical infrastructure includes things that float—and that “no environmental impact” can still be a strategic win for whoever held the keys for a day.
Source: TechCrunch — FBI, Coast Guard boarded hacked oil tankers heading toward US coast (Zack Whittaker, Sep 18, 2026).
