Iran May Have Been Hacking a Tanker Approaching the U.S. Coast

Crude Oil Crude Oil News Cyber Terrorism Cyber Warfare Exports Geopolitical Geopolitical International News Tanker Top News U.S. Energy News US Energy News

The U.S. Coast Guard and FBI boarded a Liberian-flagged very large crude carrier bound for Galveston, Texas, and a second energy tanker headed for another Texas port in the Gulf of Mexico after investigators found indications that foreign cyber actors had compromised their networks. Iranian state media claimed hackers seized control of propulsion, navigation, cargo, and communications systems. U.S. officials have confirmed malicious cyber activity, have not publicly attributed the attacks to Iran, and say the vessels were not left unsafe to navigate.

The episode is not an isolated maritime curiosity. It sits inside a broader 2026 campaign in which Iran-affiliated actors have targeted internet-exposed industrial control systems at U.S. water utilities, energy facilities, and other critical infrastructure. The question for the energy sector is no longer whether ships and plants can be reached from afar. It is how far that access can go—and whether the U.S. power grid and marine energy supply chain are prepared.

What Happened off Galveston

The first vessel is the VL Prosperity (IMO 9683697), a 333-meter (about 1,093-foot) VLCC with a deadweight of roughly 319,547 metric tons and capacity of about 2.3 million barrels of crude. It loaded near 2 million barrels at Egypt’s Sidi Kerir terminal, departed August 1, 2026, and was bound for Galveston.

Iran’s Mehr News Agency reported on August 20 that the ship suffered a “major cyberattack” on August 7 while transiting the Strait of Gibraltar and lost communications for about 30 hours. Citing an unnamed crew member, Mehr said attackers reached engine-room systems, reduced engine cooling flow, increased engine speed, and interfered with fuel and lubricating-oil systems. Tasnim, an outlet associated with the Islamic Revolutionary Guard Corps, followed with a headline arguing that “no American vessel is safe anymore.”

A specialized U.S. team—Coast Guard law enforcement, a vessel inspector, Coast Guard Cyber Protection Team members, and FBI Cyber Action Team operators—boarded the VL Prosperity on August 21 in the Gulf of Mexico and spent days examining information technology and operational technology systems. A second foreign-flagged energy vessel, identified in later reporting as the LPG carrier Kohaku, was boarded on August 24 under similar circumstances. Both ships were heading toward Texas ports.

The Coast Guard said investigators found indications the networks had been compromised by “foreign cyber actors.” Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, told CBS News that teams “did find malicious cyber activity.” Officials also said there were no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts. HMM Ocean Service, the South Korea-based manager of the VL Prosperity, confirmed the boarding and said the ship was later cleared to resume normal operations pending a final report.

U.S. agencies are investigating whether the two incidents are connected and whether Iran—or another actor exploiting the conflict between Washington and Tehran—was responsible. Attribution has not been made public. Analysts note that Iranian-linked groups have a record of overstating capabilities, and that matching tactics, techniques, and procedures can take weeks or months.

How New Is This Tanker—and Does Age Matter?

The VL Prosperity was built in 2015 at Hyundai Samho Heavy Industries in South Korea. That makes it an 11-year-old VLCC: not a rust-bucket, and not a brand-new digital-native vessel either.

Age cuts both ways.

Older ships often have more analog or isolated machinery and fewer internet-facing bridges between office IT and engine-room OT. That can make full remote command harder. Newer and mid-life tankers like a 2015 VLCC typically have integrated automation: engine control, power management, ECDIS navigation, ballast, cargo monitoring, and satellite communications (VSAT) that talk to shore. Those links improve efficiency. They also create pathways from an email, a satcom terminal, a poorly segmented network, or a vendor update into systems that affect speed, heading, cooling, and fuel.A 2015 build is squarely in the generation where connectivity is real and segmentation is uneven. That is the risk profile U.S. investigators are treating as serious even when the ship itself was not found to be in immediate physical distress.

Can Hackers Remotely Control a Tanker?

Short answer: they can disrupt and, in some architectures, influence critical systems. Full “joystick” command of a loaded VLCC from Tehran or anywhere else is much harder than Iranian headlines imply—and still dangerous enough to matter.

Modern tankers run two overlapping worlds:

IT — email, business networks, crew wifi, satcom, administrative PCs.
OT — propulsion and machinery control, steering, power management, navigation (GPS/GNSS, ECDIS, AIS), ballast, and cargo systems.

The danger is the connection between them. Grable put it directly: the concern is IT systems “connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel.” Asked whether cyber access could amount to remote hijacking, she said that was “a good way to characterize it, and yes, it is a concern.” She also noted that some of the tooling is “not necessarily that sophisticated.”

Independent experts split the difference in a useful way. Rob Lee of Dragos said the Coast Guard’s description of the risk is realistic. Quinton DuBose, a former Coast Guard cyber official, warned against the Hollywood version: ships are complicated, crews can disconnect autopilots and revert to manual control, and “I’d be kind of cautious about saying that somebody can just take control of the ship.” The more plausible attack is disruption—communications blackouts, false readings, engine-parameter changes, ballast or cargo-system interference—that makes a ship less safe to handle, especially in a strait or approaching a port.

Maritime security firm CyberOwl has said that verified remote manipulation of engine controls would be a rare, highly sophisticated event. That is the right standard. Iranian media described exactly that kind of engine-room interference. U.S. officials have confirmed compromise and malicious activity, not a public technical confirmation that cooling flow and RPM were actually rewritten from shore. Those two statements can both be true at once.

Practical takeaway for energy shipping:

  • Comms loss for 30 hours is itself an operational and safety problem.
  • GPS spoofing and GNSS interference are already common and do not require deep OT access.
  • If IT and OT are poorly segmented, an attacker may reach machinery interfaces.
  • Crew overrides still exist on conventional tankers. They are not a substitute for network hygiene.
  • A loaded VLCC near a U.S. port is a collision, explosion, fire, and channel-blockage risk even if the attacker never “steers” the ship like a drone.

Iran’s Other Front: Water Utilities

The tanker story lands after a summer of attacks on U.S. drinking and wastewater systems that officials and industry groups have tied to Iran-affiliated actors.In late July 2026, Minnesota disclosed a coordinated campaign against more than 30 community water systems. Federal and state reporting then widened the map: utilities in at least 12 states, and malicious activity affecting on the order of 100 municipalities, according to officials familiar with the investigation. Impacts included pressure drops, a pump-station shutdown in Georgia that led to a boil-water advisory, and shifts to manual operations. There have been no reported mass-casualty water-quality events. That is not the same as “no threat.”

The technical pattern is consistent. Attackers have gone after internet-exposed programmable logic controllers—the small industrial computers that run pumps, valves, and switches. CISA, FBI, NSA, DOE, and EPA advisories describe Iran-affiliated activity against Rockwell/Allen-Bradley devices, later expanding to Schneider Electric and Siemens PLCs. Actors downloaded malicious project files and manipulated HMI/SCADA displays, causing disruption and financial loss. The activity matches the operational style of CyberAv3ngers, a group U.S. agencies have linked to Iran’s IRGC. Groups including APT Iran have claimed credit for parts of the campaign.

This is more opportunistic than Stuxnet. Many small utilities still put aging PLCs on the public internet with weak or default credentials. That is low-cost disruption: a pressure drop here, a boil-water notice there, a public signal that the war can reach municipal America. Analysts have described the water campaign as much psychological as kinetic. The engineering lesson is the same as on a tanker: if the controller is reachable, the process can be nudged.

Is the U.S. Grid Vulnerable to Iran and Other Foreign Attackers?

Yes—at the edges, and in places that look a lot like those water plants. The bulk transmission system is a harder target than a small-town pump station, but it is not immune.

Joint federal advisories this year explicitly include the energy sector among targets of Iran-affiliated APT activity against internet-connected OT and PLCs. The same class of devices used in water plants is used in generation, auxiliary systems, and some distribution and industrial energy sites. In July, a small U.K. power facility was shut for four days after a suspected Iran-nexus attack; officials said the wider grid was not at risk. That is the pattern to watch: not an immediate national blackout, but successful hits on exposed generators and industrial controllers.

Why the bulk U.S. grid is tougher than municipal water:

  • NERC CIP standards impose mandatory cyber controls on bulk electric system assets.
  • Larger utilities generally have better network segmentation, monitoring, and incident response.
  • Destroying or islanding a major interconnection is a high-end, high-attribution act.
  • That being said, sleeper cells can take out local substations.

Why it is still vulnerable:

  • Thousands of smaller generators, municipal utilities, and industrial sites sit outside the hardest CIP envelope.
  • Internet-exposed PLCs, VPNs, and remote-access tools remain common.
  • Vendors and maintenance networks create supply-chain paths into OT.
  • Iran is not the only actor. Russia and China have demonstrated far more sophisticated grid-oriented tooling in other theaters. Iran’s current public campaign looks like volume and signaling.
  • That can change.

Hacktivist-style claims of “access to the power grid” should be treated as unverified until operators and agencies confirm them. The confirmed fact is narrower and more important: federal agencies say Iran-affiliated actors are already inside some U.S. energy-sector OT devices and have caused disruption.

How Prevalent Are Cyberattacks in the Marine Industry?

They are no longer rare, and they are growing faster than the industry’s defenses.

Recent industry reporting for 2025–2026 includes:

  • Maritime cyber incidents roughly doubling year over year (Cytur: about +103% in 2025).
  • Maritime OT cyberattacks up about 150%, with a large ransomware share (Cydome).
  • About one in five shipping companies reported a cyberattack in the prior 12 months (Thetius/Brookes Bell survey).
  • On the order of 1,000 GPS/GNSS disruption incidents per day, affecting tens of thousands of vessels in some tallies—jamming and spoofing, not necessarily deep OT hacks.
  • U.S. agencies tracking cyber threats involving nearly 20 vessels worldwide around the time of the Texas-bound boardings, with the Coast Guard seeking advance notice before those ships enter U.S. ports.

The 2017 NotPetya hit on Maersk remains the industry’s cautionary tale for shoreside IT cascading into operations. Since then, attackers have moved into satcom providers, ECDIS, ballast systems, and fleet-level VSAT infrastructure. In 2025, the group Lab Dookhtegan disrupted communications across a large fleet of Iranian tankers by hitting provider-level VSAT systems—an ugly demonstration that one compromised vendor can touch many hulls at once.

Energy tankers concentrate the risk. A containership losing a billing system is expensive. A VLCC losing comms in a strait, or having engine and cargo systems touched while carrying two million barrels toward a U.S. Gulf port, is an energy-security event.

Why This Matters for Energy News Beat Readers

Galveston and the Texas Gulf are not abstract waypoints. They are part of the system that moves crude, products, and LPG into the U.S. refining and petrochemical complex. A cyber incident that delays a VLCC, forces a port to manual operations, or—worst case—creates a casualty in a channel does not stay at sea. It shows up in inventories, crack spreads, and insurance.

Three points should guide operators and policymakers:

Do not take Iranian media at face value, and do not dismiss the boarding. Tehran has an incentive to advertise capability. The Coast Guard and FBI still found enough to put cyber teams on two incoming energy ships.
Segmentation is the real control. Whether the asset is a 2015 VLCC or a municipal water PLC, the failure mode is the same: business networks and the public internet reaching machines that move oil, water, or electrons.
The water-utility campaign is a rehearsal script. Low-sophistication, high-volume hits on exposed controllers are already happening in the United States. Energy and marine OT that look like those controllers will be next if they are not already.

The VL Prosperity was cleared to operate. That is the good news. The worse news is that U.S. agencies are now treating cyber compromise of inbound energy tankers as a boarding-level national security problem—and that Iran-affiliated actors have spent 2026 proving they can find the cheap doors into American industrial systems.

Making Appendices Great Again

Check out the World’s Greatest Podcast Show Notes at EnergyNewsBeat.co or EnergyNewsBeat.com.


Appendix: Sources and Links

The tanker incident

Vessel particulars (VL Prosperity, IMO 9683697)

Can ships be hacked / remote control and OT risk

Maritime cyber prevalence

Iran-linked water utility and critical infrastructure attacks

Grid / energy-sector OT vulnerability

Tagged