Hackers Breached U.S.-Bound Oil Supertanker

Investigations have not been able to determine how access was gained or who was responsible.

Hooded figure at laptop with global network connections, data analytics charts, and world map overlay representing cybersecurity and digital threats
istock.com/peshkov

It was recently confirmed that hackers were able to gain access to the digital propulsion system of the Libya-based VL Prosperity, a fully-loaded oil supertanker bound for Galveston, Texas. The hack, which occurred in August, resulted in a a 30-hour communication blackout while the vessel was transitioning through the Strait of Gibraltar.

Investigations by the FBI and U.S. Coast Guard have not been able to determine how the attackers gained access, how long they remained in the system, who was responsible, or what ship functions they may have been able to control. However, Iranian state media has made claims that these hackers manipulated the engine-room cooling flow, engine speed, and navigation/cargo systems.

The FBI and Coast Guard boarded the VL Prosperity after it lost communications and received indications that its network had been compromised. The groups reportedly spent an extensive amount of time focused on both the onboard IT and OT systems. Within a month of this incident U.S. agencies were tracking cyber threats involving nearly 20 vessels around the world, and had requested advance notice if any planned to enter a U.S. port. 

Currently, according to reports from Bloomberg, the VL Prosperity remains anchored offshore near Galveston as the investigation continues. Maritime threats represent a new target for state-sponsored hacking groups, and are garnering more attention from the industry as a whole.

"If investigators can show that an intruder reached a write-capable propulsion controller and issued a valid command, this would be the first publicly documented, independently confirmed cyberattack against a commercial vessel’s propulsion controls," offers Suzu Labs' Jacob Krell. "That is a much bigger claim than temporary access to a digital system," he continues.

“That distinction matters because a propulsion-related bridge console, engineering workstation, machinery automation gateway, and engine controller are materially different findings," states Krell. "The U.S. Coast Guard’s 2019 response to a malware incident aboard a deep-draft vessel is the useful comparison. The malware seriously degraded the ship’s onboard computer network, but investigators found that essential vessel control systems were unaffected. Maersk made a similar distinction during the 2017 NotPetya attack."

“The rapid escalation from a single novel maritime intrusion to federal tracking of nearly 20 compromised vessels directly threatens an already precarious global oil market, creating upward pressure on crude prices and downstream refined products," adds Damon Small from Xcape, Inc. "These supertankers operate as self-sufficient floating cities governed by complex operational technology systems that manage crew life support, navigation, and critical cargo onboarding and offboarding." 

Small also offered these critical takeaways from the VL Prosperity incident:

  • Global tracking of nearly 20 compromised vessels shifts maritime cyber risk from an isolated novelty to a material supply chain threat capable of driving up global oil prices.
  • Supertankers rely on interconnected OT for life support, propulsion, and cargo operations, making unauthorized access to onboard control networks potentially devastating to fleet operations.
  • Security teams must enforce strict network segmentation between bridge IT, satellite communications, and OT systems, backed by unidirectional gateways and continuous industrial network monitoring.
  • Air-gapping vessel networks only works if you do not run an ethernet cable straight from the satellite dish to the propulsion engine.
More in Cybersecurity