> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
- URL: https://f4n6.co.uk/security-feed/coast-guard-fbi-boarded-tanker-after-attack-by-foreign-cyber-actors/
- Published: 2026-09-16T20:46:50.000Z
- Updated: 2026-09-16T20:46:50.000Z
- Author: Jeff Davies
- Tags: #security-feed

## 1\. Executive summary

The U.S. Coast Guard confirmed it boarded an oil tanker in the Gulf of Mexico on 21 August 2026 after indications that the vessel's network "were compromised by foreign cyber actors," deploying a joint team of Coast Guard Law Enforcement, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators. The Wall Street Journal reported at least two tankers bound for the U.S. were hit by cyberattacks, with a second boarding on 24 August; Bloomberg identified one vessel as the Liberian-flagged VL Prosperity, which an Iranian state-aligned outlet said lost communications for 30 hours. No hacking group has claimed credit and no attribution has been confirmed by U.S. authorities — the "foreign cyber actors" phrasing is the Coast Guard's, and the Iran linkage rests on a single Iranian outlet citing unnamed Russian analysts. No CVSS score, CVE, CISA-KEV entry or exploitation state is available for this item; it is a maritime OT/IT intrusion reported at the incident level, not a vulnerability disclosure. Direct risk to EMEA financial services is indirect: exposure runs through trade finance and commodity shipping books, marine and cargo insurance, and any reliance on port, terminal or maritime-logistics ICT providers.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item.

This is a U.S. maritime security incident involving a Liberian-flagged vessel and U.S. port infrastructure. Nothing in the source establishes that an EMEA financial entity's own ICT systems, an ICT third-party provider under DORA Art. 28/30 contract, or an entity in scope of NIS2 Art. 21(2)(d) or UK NIS 2018 was affected. Mapping DORA Art. 17–19 or NIS2 Art. 23 here would be compliance-checkbox padding: the trigger facts (a foreign-flagged tanker boarded in the Gulf of Mexico; a U.S. port operator shifting to manual operations) do not by themselves create a reporting or testing obligation for an EMEA client. Clients with material maritime counterparty exposure should treat this as a third-party risk *monitoring* input under their existing DORA Art. 28/29 processes, not as an incident that triggers a filing.

## 3\. Technical analysis & attack chain

The source material does not contain a confirmed attack chain. No initial access vector, exploited component, CVE, malware family, payload, persistence mechanism, C2 infrastructure or exfiltration path is described. What follows is the confirmed sequence of events, then the unconfirmed technical claims, clearly separated.

### Confirmed timeline (multi-source, U.S. Coast Guard on record)

1. **6 August 2026** — North Carolina Ports reports a cyberattack that forced a shift to manual operations. A port spokesperson states its IT system was "hacked by an outside actor or group," requiring activation of a contingency plan and contact with multiple state agencies and the U.S. Coast Guard. No link to the tanker incidents has been established by any source.
2. **21 August 2026** — A U.S. Coast Guard boarding team embarks a tanker in the Gulf of Mexico to "ensure integrity of the vessel's operational and information technology systems following indications that the vessel's network were compromised by foreign cyber actors." Team composition: USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators.
3. **24 August 2026** — The Wall Street Journal reports a second ship was boarded. The Coast Guard did not confirm whether either boarding involved VL Prosperity.
4. **Ongoing** — Coast Guard states it is working with port operators, vessel owners and local maritime stakeholders to "ensure port operations continue safely and without interruption." Coast Guard states there are "no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts."

### Unconfirmed / single-sourced claims — treat with caution

The technical detail that would matter most to a defender is the least corroborated. An Iranian government-backed outlet, Mehr, reported that VL Prosperity — Liberian-flagged, transiting from an Egyptian port to a U.S. port — was attacked on **7 August 2026 while transiting the Strait of Gibraltar**, and that a crew member alleged the attackers were able to **increase the engine speed and disable the ship's fuel and engine-oil tank**, with the vessel losing communications for **30 hours**. If accurate, this describes manipulation of vessel control/OT systems and deliberate communications denial rather than a purely administrative IT compromise — a materially different severity profile. This claim is single-sourced to a state-aligned outlet and is contradicted in part by the Coast Guard's statement that there were no operational disruptions; both statements can be reconciled only if the effects were transient or confined to the vessel rather than port operations, but that reconciliation is inference, not fact. Bloomberg's identification of VL Prosperity as one of the affected tankers is a second outlet but does not independently corroborate the engine/comms claims. Mehr further cited unnamed Russian analysts linking the incident to the U.S.–Iran military conflict; **no hacking group has taken credit**, and the Coast Guard declined to answer questions on the nature of the attack or who was behind it. **Attribution is unconfirmed. No MITRE ATT&CK group profile is associated with this item.**

**Context, not linkage:** the article notes that U.S., European and Asian ports have been repeatedly targeted by ransomware gangs over the past five years — Port of Seattle (2024, ransom refused), European ports plus Royal Dirkzwager and DNV (2023), Oiltanking and Mabanaft force majeure (2022), and Expeditors International (2022). **Nothing in the source indicates the tanker incidents involved ransomware, data theft or extortion.** Do not characterise this as a ransomware event.

## 4\. Mitigation & containment

There is no vendor fix, patch or version guidance in the source — this is not a vulnerability item. Actions below are scoped to the exposure an EMEA financial services client actually has: counterparty, insurance and third-party ICT risk.

### P1 — within 24 hours

- Identify any open trade-finance, commodity-shipping, charter, marine/cargo insurance or letters-of-credit exposure to **VL Prosperity**, its owner/operator, or voyages routed Egypt → U.S. transiting the Strait of Gibraltar on or after 7 August 2026\. Escrow, documentary-credit and collateral positions tied to affected cargo should be reviewed for delivery and force-majeure risk.
- Confirm whether any in-scope ICT third-party provider (port terminal operator, maritime logistics platform, AIS/vessel-tracking data vendor, freight-forwarding system) is named in the incident or has disclosed an impact. If a provider is affected, invoke the incident-notification clause in the DORA Art. 30 contract and record the notification timestamp.
- Do not act on the Iran-attribution claim. It is single-sourced to a state-aligned outlet citing unnamed analysts; no group has claimed credit and no government has confirmed it.

### P2 — within 72 hours

- For any confirmed provider exposure, run the standard third-party incident questionnaire: scope of compromise, whether OT/vessel-control systems were reachable from the compromised network, containment status, and expected restoration timeline.
- Review marine and cargo insurance counterparty concentration — if multiple policies or facilities reference the same vessel operator, manager or flag-state administrator, treat as a concentration point under the DORA Art. 29 preliminary assessment process.
- Brief trade-finance operations on callback verification for any payment-instruction change referencing affected voyages or counterparties. Maritime incidents are a recurring pretext for invoice and payment-diversion fraud; the source does not report fraud here, but the operational window is open.

### P3 — within 7 days

- Add maritime/port/logistics ICT providers to the third-party register with a risk rating reflecting this incident class, and confirm each has a contractual breach-notification obligation.
- Table a scenario exercise for the next resilience test cycle: sustained loss of a port or shipping-logistics provider, covering manual fallback for trade-finance settlement and documentary processing.

## 5\. Indicators of compromise

No indicators of compromise available in the source material. No hashes, domains, IP addresses, file paths, registry keys, mutexes, scheduled-task names or command-line artefacts are present in any source.

The sources describe observable **behaviours**, but none are atomic indicators and none are observable in an EMEA financial institution's own telemetry. They are recorded below for maritime-exposed clients only, and all are single-sourced.

### Behavioural indicators

| behaviour                                                              | where to observe                                                            | confidence                                                                                |
| ---------------------------------------------------------------------- | --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Vessel loses communications for \~30 hours                             | Vessel AIS/telemetry feed, owner/operator reporting, voyage-tracking vendor | Low — single-sourced to Mehr (Iranian state-aligned outlet), citing a crew member         |
| Unexpected increase in engine speed; fuel and engine-oil tank disabled | Vessel OT/engine-control logs, owner/operator incident report               | Low — single-sourced to Mehr; contradicted by USCG statement of no operational disruption |
| Port IT system compromised, operations shifted to manual               | Port operator disclosure, port authority advisory                           | Medium — port spokesperson on record, but no established link to the tanker incidents     |
| U.S. Coast Guard / FBI cyber boarding of vessel                        | Port state control records, USCG marine safety advisories                   | High — USCG spokesperson on record                                                        |

## 6\. Detection

Insufficient indicators to author detection rules.

No threat artefacts — no strings, command-line flags, mutexes, file names, registry keys, ransom-note text or hard-coded values — appear in the source material. Any rule built from this item would grep for reporting *about* the incident (vessel names, agency names, CVE-free prose) rather than for the threat itself, and is therefore not emitted.

## 7\. Sources

- Recorded Future News (The Record) — *Coast Guard, FBI boarded tanker after attack by 'foreign cyber actors'*, Jonathan Greig — https://therecord.media/oil-tanker-cyberattack-coast-guard-fbi — 2026-09-16
- Secondary outlets referenced within the above article, not independently retrieved by Adverse Trace: Wall Street Journal (second boarding, 24 August; at least two tankers affected), Bloomberg (identification of VL Prosperity; vessel position off the coast of Texas), Mehr (Iranian government-backed; 30-hour communications loss, engine-speed and fuel-tank claims, Strait of Gibraltar transit on 7 August). URLs not available in the supplied material.

## 8\. Adverse Trace position

**Severity: not assessable by CVSS.** No CVE, CVSS score, severity rating, EPSS value or CISA-KEV entry exists for this item — it is an incident report, not a vulnerability disclosure, and we will not manufacture a score to fill the field. Qualitatively, the *claimed* effects (manipulation of vessel engine controls, 30-hour communications blackout) would be high-impact OT compromise if true, but those claims are single-sourced to an Iranian state-aligned outlet citing unnamed Russian analysts, are partially contradicted by the U.S. Coast Guard's statement of no operational disruption, and carry no independent corroboration. **Attribution is unconfirmed:** the Coast Guard's "foreign cyber actors" phrasing is not an attribution, no group has claimed credit, and no MITRE ATT&CK group profile is associated with this item — clients should not act on the Iran linkage. **Client impact for EMEA financial services is indirect and counterparty-driven**, running through trade finance, commodity shipping, marine/cargo insurance and port or maritime-logistics ICT providers; there is no direct technical exposure to patch or block. **Next steps:** we are monitoring for a Coast Guard Marine Safety Advisory, an FBI or CISA statement, or a named-actor claim; we will reissue this advisory if attribution firms up, if a second independent source corroborates the OT-control claims, or if an EMEA-regulated ICT provider is named. Clients with material maritime counterparty exposure should complete the P1 counterparty and provider checks in §4 and treat the attribution question as open.

---

[Read the original source →](https://therecord.media/oil-tanker-cyberattack-coast-guard-fbi?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*