US Coast Guard, FBI Board Two Ships After Suspected Cyberattack in Gulf of Mexico
US authorities confirmed Coast Guard and FBI teams boarded two foreign-flagged commercial vessels in the Gulf of Mexico after indications their computer networks were compromised, highlighting growing cyber risks to global shipping amid geopolitical tensions.
US authorities have confirmed that the Coast Guard and FBI boarded two foreign-flagged commercial vessels bound for the United States after receiving indications that hackers had compromised their computer networks.
The unusual operations took place in the Gulf of Mexico on August 21 and August 24, highlighting growing cybersecurity concerns across the global shipping industry amid heightened geopolitical tensions and the wider US-Iran conflict.
Why Did US Authorities Board the Ships?
The FBI said joint teams from the Coast Guard and the bureau boarded the two vessels after receiving “indications that the networks of both vessels were compromised.”
The Coast Guard separately confirmed the August 21 boarding, saying that “foreign cyber actors” were involved.
Neither agency publicly identified the suspected hackers or provided details about how the networks were compromised.
The agencies also did not explain why their public accounts differed slightly regarding the number and dates of the boardings.
One Vessel Identified as Liberian-Flagged VL Prosperity
Maritime security company Dryad Global identified one of the vessels as the Liberian-flagged VL Prosperity.
Ship-tracking data showed the vessel anchored near Galveston, Texas.
The vessel had reportedly experienced a major cyber incident before reaching US waters. Iran's Mehr news agency reported on August 20 that the ship suffered what it described as a “major cyberattack” while transiting the Strait of Gibraltar.
According to the report, the attack disrupted the vessel's communications for approximately 30 hours.
Alleged Attack on Ship’s Engine Systems
Mehr, citing an unnamed crew member, reported that the hackers may have gained access beyond the ship's communications systems.
The report alleged that attackers:
- Infiltrated engine-room systems.
- Reduced the flow of engine cooling systems.
- Increased the ship's engine speed.
- Disabled systems associated with fuel and engine-oil tanks.
However, the Iranian news report did not identify who was responsible for the alleged attack, and US authorities have not publicly confirmed these specific claims.
The reported intrusion therefore remains separate from the US agencies' confirmation that the vessels' computer networks had been compromised.
Shipping Industry Faces Growing Cyber Risks
The incidents highlight the increasing vulnerability of commercial shipping to cyberattacks.
Modern vessels rely heavily on interconnected digital systems for navigation, communications, propulsion, cargo management and other operations. A successful intrusion could therefore potentially disrupt a vessel's operations or create safety risks.
Corey Ranslem, CEO of Dryad Global, said ship-focused cyberattacks are not particularly difficult to conduct and warned that similar incidents could become more common.
“We are expecting these types of attacks to continue and will expand in the very near future,” Ranslem said.
Iran Conflict Adds to Cybersecurity Concerns
The vessel incidents come amid heightened cybersecurity concerns following the outbreak of the US-Iran conflict in February.
US authorities have dealt with a series of cyber incidents that media reports have linked to Iran during the conflict. However, attribution in cyber operations can be difficult, and public confirmation of responsibility does not necessarily accompany individual incidents.
The suspected compromise of commercial vessels adds another dimension to the broader security risks surrounding international maritime trade.
What Remains Unclear
Several important details remain unknown.
US authorities have not publicly identified the two vessels involved, apart from the identification of VL Prosperity by Dryad Global. They have also not disclosed the specific systems that were compromised, the extent of any operational disruption or whether investigators have identified the perpetrators.
It is also unclear whether the alleged cyberattack reported by Mehr was the same incident that prompted the US boarding operation.