US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.
The VL Prosperity – a Liberian-flagged supertanker carrying roughly 2.

US Coast Guard and FBI board oil tanker to investigate cyber attack

US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity – a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil – apparently suffered a cyber attack while en route from Egypt’s Sidi Kerir oil terminal to Galveston, Texas.

Having left Egypt on August 1, the tanker was passing through the Strait of Gibraltar a week later when hackers allegedly managed to penetrate its systems, interfering with the fuel systems and engine speed, as well as cutting communications for 30 hours.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network “may have been compromised by a foreign actor,” but reports that there was no disruption to operations, injuries, or environmental impact.

As ever in cybersecurity, attribution is a murky and often imprecise business. Nonetheless there will – no doubt – be speculation that Iranian-backed hackers may have been responsible for the attack, although no evidence for this has been presented.

What is perhaps more important is not who hacked the supertanker, but just how easy it might be to disrupt a ship’s satellite communications and the systems that keep it safe.

Operational technology expert Rob Lee told CBS News that even large supertankers may have a shared network for navigation, propulsion, steering, and ship command – all protected behind a single firewall. Once the boundary has been breached, a malicious hacker could potentially interfere with the technology steering a supertanker.

Rear Admiral Amy Grable, commander of US Coast Guard Cyber Command, told CBS News that attacks do not need to be sophisticated to succeed. She went on to explain that malicious source code that can assist cybercriminals is readily available for hackers and that “artificial intelligence is accelerating the rate at which we need to take action.”

Whether an attacker could simply commandeer a supertanker and sail it wherever they wanted by remote control is perhaps unlikely, but it is more plausible that they could disrupt systems to such an extent that a vessel might become unsafe to handle.

The biggest threat perhaps is that with trillions worth of dollars moving through US ports annually, even a modest disruption could have serious consequences.

For now, the advice appears to be straightforward and familiar. Grable advocates enhancing cybersecurity through network segmentation, raising awareness of phishing attacks, and basic cyber hygiene.

She went on to add, “Just taking basic precautions would prevent most of these occurrences.”

That is good advice – not just for oil tankers carrying a few hundred million dollars worth of crude oil, but also for the rest of us landlubbers sat at our office desks and in our homes.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.