The United States is reportedly investigating whether Iran was behind cyberattacks on two energy tankers traveling toward Texas after U.S. Coast Guard and FBI teams boarded the vessels in the Gulf of Mexico.
The Wall Street Journal reported on September 16 that U.S. officials familiar with the investigation are examining a possible Iranian role in the attacks.
The two vessels were targeted while transiting the Strait of Gibraltar in early August before continuing toward the United States.
One of the vessels was the VL Prosperity, a 333-meter Liberian-flagged crude oil tanker carrying more than 2 million barrels of oil from Egypt toward Galveston, Texas, according to vessel-tracking data cited by the Journal and CBS News. The ship departed Egypt’s Sidi Kerir terminal on August 1.
Iran’s semiofficial Mehr News Agency reported on August 20 that the VL Prosperity had been attacked on August 7 while sailing through the Strait of Gibraltar.
Citing an unnamed crew member, Mehr said the attackers interfered with engine-room systems, including engine cooling, engine speed, fuel, and lubricating oil. It also reported that the ship lost communications for about 30 hours.
The U.S. response came on August 21, when a specialized Coast Guard team that included law-enforcement personnel, a vessel inspector and cyber specialists, along with FBI Cyber Action Team operators, boarded the tanker. Investigators examined its information-technology and operational-technology systems and worked with the crew and operators to remove the threat.
Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, said investigators found evidence of malicious cyber activity.
The Coast Guard said there were no reports of operational disruption, vessel instability, physical danger to the crew or environmental damage. It has not publicly confirmed that hackers took control of the vessel’s propulsion, navigation or cargo systems, despite the claims made by Iranian media.
The second vessel was identified by the Journal as the Kohaku, which was transiting the Strait of Gibraltar toward another Texas port to load liquefied petroleum gas, according to vessel-tracking data and a U.S. official.
A Coast Guard vessel that had responded to the VL Prosperity later approached the Kohaku. U.S. Coast Guard and FBI statements said the boarding of the second vessel took place on August 24 after indications that its network had also been compromised.
The incidents have drawn particular attention because the suspected attacks occurred far from the Middle East while the vessels were ultimately bound for U.S. ports.
U.S. investigators are examining whether the two incidents were connected and whether Iran or another foreign actor was responsible.
Grable said investigators compare the techniques used in a cyberattack with those used by known threat actors when attempting to establish attribution, a process that can take weeks or months.
Iranian state media gave the VL Prosperity incident prominent coverage before U.S. authorities publicly disclosed the boardings. Four days after Mehr’s report, Tasnim News Agency published an article portraying the incident as an example of cyber operations becoming part of maritime warfare.
The investigation comes as U.S. officials face growing concerns over the vulnerability of commercial vessels whose navigation, communications, machinery and other functions increasingly depend on interconnected computers.
Coast Guard officials have warned that a sufficiently serious intrusion could interfere with systems that affect a vessel’s safe operation, although there is no public evidence that such consequences occurred in these incidents.
The latest incidents point to a broader emerging threat. The cyber domain could give Iran the ability to disrupt commercial shipping far beyond the Middle East, extending the reach of its maritime pressure without requiring a physical attack in the region.
_______________________________________________________________________________________________________________________
SouthFront: Analysis and Intelligence
NOW hosted at southfront.press
Previously, SouthFront: Analysis and Intelligence was at southfront.org.
The .org domain name had been blocked by the US (NATO) (https://southfront.press/southfront-org-blocked-by-u-s-controlled-global-internet-supervisor/) globally, outlawed and without any explanation
Back before that, from 2013 to 2015, SouthFront: Analysis and Intelligence was at southfront.com


