US investigating Iran ties to cyberattack on energy tankers bound for American ports - report
The United States is investigating whether Iran was behind cyberattacks on two energy tankers bound for American ports that were struck while transiting the Strait of Gibraltar in August, The Wall Street Journal reported on Thursday, citing US officials familiar with the investigation.
The incidents have raised concerns among US officials that Tehran or an Iran-aligned actor could be seeking new ways to expand attacks on global energy shipping beyond the Middle East's existing maritime flashpoints.
The ships, an oil tanker and a liquefied petroleum gas carrier, were traveling toward ports in Texas when they were targeted in early August, according to vessel-tracking data and officials cited by the WSJ.
A specialized US Coast Guard team, joined by FBI agents, boarded both vessels after they arrived in the Gulf of Mexico later that month. Investigators examined their information technology and operational systems after authorities found indications that the ships' networks had been compromised.
Rear Adm. Amy Grable, commander of the Coast Guard's Cyber Command, declined to discuss the specific vessels but told the WSJ that cyber response teams spent three to four days aboard the ships assessing the incidents and ensuring that they could continue operating safely.
Cyberattack risks aboard modern tankers
“Unfortunately, many ships’ IT systems are interconnected with other systems on a ship, the systems that control the engineering plant, propulsion, navigation, et cetera,” Grable said. “So if those systems can be breached and controlled, then the crews could lose control of the vessel, and it could cause a mishap or a collision. And that’s what we’re looking for.”
One of the vessels, the VL Prosperity, was carrying more than two million barrels of oil from Egypt to Galveston, Texas, when it was targeted in the Strait of Gibraltar, according to Lloyd's List Intelligence tracking data and a US official cited by the WSJ.
Iran's semiofficial Mehr News reported in August that hackers had infiltrated the VL Prosperity's engine-room systems, reduced engine cooling flow, increased the engine's speed, and interfered with fuel and engine-oil systems. No organization claimed responsibility for the attack, and the WSJ said it could not independently verify the account.
The VL Prosperity's manager confirmed that US authorities conducted a cybersecurity inspection aboard the vessel and said it was subsequently cleared for normal operations.
The second vessel, the Kohaku, was passing through the Strait of Gibraltar on its way to another Texas port, where it was scheduled to load liquefied petroleum gas. Tracking data showed that it was approached by the same Coast Guard vessel involved in the response to the VL Prosperity.
The Coast Guard has said there were no reports of operational disruptions, vessel instability, physical danger to crew members, or environmental damage following the incidents. US authorities have not publicly attributed the cyberattacks to Iran.
Maritime trade routes play key role in US-Iran conflict
The investigation comes as maritime routes have become a central arena in the conflict between Washington and Tehran. Shipping through the Strait of Hormuz has faced repeated attacks and severe disruption during the fighting, with commercial vessels reducing transit through the strategically important waterway.
Earlier this week, an oil tanker was attacked in the Strait of Hormuz, with US Central Command saying the vessel had recently been struck by an Iranian drone. Iranian authorities offered a different account of the incident.
The Iran-backed Houthis have meanwhile intensified pressure on shipping around the Red Sea. The group has sought greater control around the Bab al-Mandab Strait and Yemen's western coast, another major chokepoint for global commerce and energy shipments.
US officials' concern over the tanker incidents reflects the potential consequences of moving such attacks into the cyber domain. Modern ships rely on interconnected digital systems to control propulsion, navigation, engineering and cargo operations, meaning that a successful intrusion could potentially cause a collision, fire, explosion or environmental disaster.
The threat comes amid broader concerns over Iranian cyber activity. The US, UK and Netherlands this week issued a joint warning over Iranian state-linked cyber operations targeting journalists, activists and other individuals.
Rear Adm. Jason Tama, head of Coast Guard Cyber Command, previously warned that cyber interference aboard oil tankers could pose particularly serious risks because of the nature of their cargo.
“For a vessel that’s carrying tens of millions of gallons of crude oil, which is highly volatile, there’s always a risk of fire or explosion,” Tama told the WSJ in June. “The atmosphere in the tanks has to be very carefully managed to ensure that you’re not going to get a situation where there’s a fire or explosion. And then there’s always a risk of an oil spill.”
US authorities have not disclosed how many suspected maritime cyberattacks they have investigated since the war with Iran began or whether investigators have established a connection between the attacks on the two tankers.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.