Critical Infrastructure

USCG + FBI boarded a US-bound tanker after foreign cyber actors hit the network

Coast Guard confirms an Aug 21 Gulf of Mexico cyber boarding with FBI Cyber Action Team. WSJ: second boarding Aug 24. No ops, crew, or environmental impact reported. Attribution Undisclosed.

Sep 16, 2026 · 3 min read

Maritime cyber just got an official U.S. boarding stamp — not a rumor-mill slide.

On September 16, 2026, after The Wall Street Journal reported that at least two U.S.-bound tankers were hit with cyberattacks, a U.S. Coast Guard spokesperson confirmed that on August 21 a specialized team boarded a foreign-flagged commercial vessel in the Gulf of Mexico. The team included USCG law-enforcement personnel, a USCG Cyber Protection Team, a vessel inspector, and FBI Cyber Action Team operators. Purpose, in the Coast Guard’s words: ensure integrity of the vessel’s operational and information technology systems “following indications that the vessel’s network were compromised by foreign cyber actors.”

Same statement: no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts. The Coast Guard said it continues to work with port operators, vessel owners, and local maritime stakeholders so port operations stay safe and uninterrupted. The Record notes the Coast Guard did not answer questions on attack technique, who was behind it, or whether the Aug 21 boarding was the Liberian-flagged VLCC VL Prosperity — a name Bloomberg has used and Iranian state outlet Mehr has amplified with claims of a ~30-hour communications outage near Gibraltar. Treat ship identity and OT-effect claims as secondary / unconfirmed by USCG until the U.S. names the hull.

WSJ reporting (via The Record / CyberScoop / ABC) puts a second joint boarding on August 24; public U.S. attribution remains Undisclosed. ABC sources say investigators are looking at possible Iran-linked or conflict-opportunist actors — that is sourcing color, not a government attribution. No hacking group has publicly claimed the incidents.

POV: energy shipping OT/IT is now a boarding-and-forensics problem at the Gulf approaches, not only a SOC ticket. Underwrite the Coast Guard’s confirmed compromise indications + joint USCG/FBI boarding + “no ops impact” line. Leave hull names, engine-room folklore, and nation-state labels as attributed secondary claims. Operators: treat inbound energy carriers with foreign-cyber indications as a port-cyber coordination event, not a PR footnote.

Sources