The US is investigating a possible Iran link to cyberattacks on two Texas-bound energy tankers after Coast Guard and FBI teams found evidence of malicious cyber activity. Officials have not attributed the attacks to Tehran, but the incidents are raising concerns about maritime cyber threats and critical infrastructure.
Tanker cyberattack triggers US investigation
US Coast Guard personnel and FBI cyber specialists boarded two foreign-flagged energy vessels in August after receiving indications that their networks may have been compromised while they were heading toward the United States.
One vessel was the Liberian-flagged VL Prosperity, a 1,093-foot crude oil supertanker capable of carrying about 2.3 million barrels. Coast Guard and FBI personnel boarded it on August 21 and examined its information technology and operational systems over several days. A second tanker was boarded on August 24.
Rear Adm. Amy Grable of US Coast Guard Cyber Command said investigators found malicious cyber activity but no evidence that the vessel was unsafe to operate when teams arrived. The US is examining whether the two incidents are connected and whether a foreign government or other actor was responsible.
Iran link remains under investigation
US authorities have not publicly blamed Iran for either tanker cyberattack. That distinction is important because attribution in cyber investigations can take weeks or months as specialists compare malware, tactics and digital infrastructure with known threat actors.
Iranian state media reported earlier that VL Prosperity had suffered a major cyberattack near the Strait of Gibraltar on August 7. Mehr News Agency claimed hackers accessed engine-room systems, altered cooling flow and engine speed, interfered with fuel systems and caused a communications blackout lasting about 30 hours. Those technical claims have not been independently confirmed by US investigators.
The ship had left Egypt’s Sidi Kerir terminal on August 1 and was bound for Galveston, Texas. US investigators are now considering Iran alongside other possible foreign adversaries, but no responsible party has been identified.
Maritime cyber risk grows with connected ships
Modern commercial vessels increasingly depend on connected systems for navigation, propulsion, steering, ballast and cargo operations. That connectivity improves efficiency but also creates new entry points for hackers.
Grable warned that a successful breach could potentially cause a collision, block a shipping channel, disrupt port activity or trigger a pollution incident. Even an attack that does not damage a vessel could generate major economic losses if shipping traffic is delayed.
The threat is especially significant for oil and energy shipping because major ports and waterways are critical parts of global supply chains.
FBI warnings widen critical infrastructure concerns
The tanker investigation adds to broader US concern about attacks on critical infrastructure. Federal agencies have repeatedly warned operators to strengthen network segmentation, patch vulnerable systems, improve phishing defenses and separate internet-facing networks from operational technology.
For maritime operators, the latest cases offer a clear warning: cyber incidents no longer affect only office networks or communications systems. A breach that reaches operational controls could create physical safety, environmental and economic risks.
The immediate investigation remains focused on determining how the tanker networks were accessed, whether the two incidents share a common source and whether Iran or another actor was involved. Until investigators release attribution evidence, describing the attacks as Iranian remains unproven.
Relevant internal links could point to World News, Cybersecurity, Iran, US News, Energy and Shipping sections, along with previous coverage of critical infrastructure attacks and maritime security.