The U.S. Coast Guard and FBI boarded two foreign commercial tankers in the Gulf of Mexico on August 21 and 24 after indications their networks had been compromised. Coast Guard Cyber Protection Teams and the FBI Cyber Action Team examined both vessels’ operational technology and IT environments; one potentially affected ship was identified as the Liberian-flagged VL Prosperity, which reportedly lost communications for more than 30 hours following an August 7 intrusion while transiting the Strait of Gibraltar from Egypt to the United States.
Authorities said the incidents caused no confirmed disruption to vessel operations, instability, crew safety risk, or environmental harm, and they have not publicly attributed the activity. Investigators reportedly considered possible Iranian involvement or a group seeking to exploit U.S.-Iran tensions, while maritime agencies coordinated with stakeholders to maintain safe, uninterrupted port operations amid separate reported cyber disruption affecting North Carolina Ports.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
President Joe Biden signed a 2024 executive order granting the U.S. Coast Guard additional authority to respond to cybersecurity incidents. The order warned that maritime cyber incidents could cause cascading harm to the global supply chain.
A similar joint Coast Guard and FBI team boarded a second foreign commercial vessel in the Gulf of Mexico to investigate another suspected network compromise.
A joint U.S. Coast Guard and FBI team boarded a foreign commercial vessel in the Gulf of Mexico after indications its network had been compromised. The team examined the vessel's operational-technology and IT environments.
The Liberian-flagged VL Prosperity was reportedly targeted while sailing from Egypt to the United States through the Strait of Gibraltar, losing communications for about 30 hours. A crew member alleged that the attackers increased engine speed and disabled the vessel's fuel and engine-oil tank.
North Carolina Ports reported that an outside actor or group compromised its IT system, prompting the port authority to enact its contingency plan and move to manual operations. It contacted state agencies and the U.S. Coast Guard.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecyberscoop.com
Open sourcebloomberg.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.