In late August 2026, the U.S. Coast Guard and the FBI boarded a Liberian-flagged crude oil carrier in the Atlantic Ocean after detecting signs that its onboard network had been compromised. The ship was later identified in Iranian state media, and by Bloomberg, as the VL Prosperity, a 333-meter supertanker bound for Galveston, Texas, with an estimated 2.3 million barrels of oil aboard.
According to the Coast Guard, a specialized team comprising Coast Guard law enforcement personnel, a vessel inspector, the Coast Guard's Cyber Protection Team and FBI Cyber Action Team operators boarded the vessel on August 21 to examine both its operational technology (OT) and information technology (IT) systems. Reporting in the Wall Street Journal, cited by the Maritime Executive, indicates a second vessel, a liquefied natural gas (LNG) carrier that has not been publicly named, also notified authorities of a suspected cyberattack around August 24.
A third case followed in September. The LNG carrier Vivit Africa LNG, which had loaded cargo at Louisiana’s Cameron LNG terminal and was bound for the Italian offshore terminal at Rovigo, reported that its crew had suddenly lost access to some internal control systems while transiting the Mediterranean and Adriatic in early September. The ship idled off the Italian coast without discharging its cargo, then began sailing back toward Algeciras, Spain. The Italian Coast Guard assisted after the master reported a malfunction in the systems used to monitor cargo parameters, and the Chioggia Coast Guard issued an urgent notice to mariners to keep their distance. No one has been publicly identified as responsible, and Bloomberg reports that U.S. officials are now tracking nearly 20 ships worldwide for possible cyber threats.
Cyberattack Attribution and Success Disputed
The Coast Guard has said there are "no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts," and no agency has publicly attributed the intrusion to a specific actor. Iranian state media claimed the tanker lost communications for 30 hours while transiting the Strait of Gibraltar on August 7, and alleged that attackers reached engine room systems, including cooling flow and fuel and lubricating oil controls.
None of those specifics have been independently confirmed. Rear Adm. Amy Grable, who commands U.S. Coast Guard Cyber Command, did tell CBS News that the boarding team assessed the vessel's IT and other onboard systems and found malicious cyber activity stressing that the team found no evidence the ship had become unsafe to navigate. The VL Prosperity has remained anchored off the Texas coast since the incident became public.
Set aside, for now, whether the intrusion happened exactly as Iranian media described it. What's confirmed is significant on its own: federal agencies had to physically board a moving commercial vessel to determine what was actually on its network. That's not an isolated response. Grable told CBS News that this was one of roughly 40 to 50 missions her Cyber Protection Team has run in the past year. What made the VL Prosperity case different was the profile: a named supertanker, direct FBI involvement and a geopolitical backdrop involving Iran.
Ships: The Last Unmonitored Link in the Energy Supply Chain
Wellheads, pipelines, terminals and refineries have spent the better part of a decade building out OT monitoring programs, largely in response to regulation that followed real incidents. A well-documented case: in 2020, ransomware delivered through a spearphishing link crossed from the IT network into the OT network of a natural gas compression facility, reaching HMIs, data historians and polling servers because the two networks weren't properly segmented. The facility's programmable logic controllers were never affected, and the operator never lost control of the process, but it shut the facility down for roughly two days out of caution while it determined what had actually been reached. Pipeline operators and utilities responded by building continuous, passive network monitoring into their compliance programs, not because the technology was new but because the lack of visibility had become too costly to ignore.
Nozomi Networks is the only OT security vendor with a hybrid platform that can be run on the cloud but can be reverted to completely on-premises operation. For a fleet operator, that means one platform covering connected ships, disconnected ships, terminals, and the shore-side operations center.
The vessel carrying crude between those points has largely been excluded from such protection. A tanker engine room, cargo management, ballast, navigation and communications systems are as networked, and often as poorly segmented, as anything found in a refinery, but few operators apply the same continuous monitoring to them. When the Coast Guard and FBI needed to know what was actually happening on the VL Prosperity's network, they had no way to do so except by sending a team to look. The Vivit Africa LNG shows the same gap from the other direction. Technicians from the company attended the vessel, the Italian Coast Guard assisted, and the cause still could not be identified. Without a record of what the control network was doing before and during the failure, a cyber incident and an equipment fault look the same from the bridge, and the operator has to choose between an expensive assumption and an expensive investigation.
Sure enough, once aboard, the team assessed the IT and OT systems, found evidence of malicious activity, and the Coast Guard has said it will give the operator recommendations for what to patch. An inspection occurred two weeks after the date Iranian media gave for the intrusion. Meanwhile, the ship sat at anchor off Galveston waiting to be declared clean. Baltic Exchange data cited by Seatrade Maritime put implied VLCC time charter equivalents (TCEs) near $170,000 per day at the end of February 2026, up from just under $40,000 in early January, with Arabian Gulf to China voyages assessed around $209,000. Rates move constantly and the charter decides who absorbs a delay, but network monitoring is a fixed annual line item while idle vessel time is a daily cost that tracks the market. That is the cost comparison worth putting in front of a CFO.
Regulation Is Catching Up, One Vessel Type at a Time
Nozomi Networks has been tracking this gap for several years. Our 2022 analysis of maritime cybersecurity readiness pointed to IMO's cyber risk management guidance and BIMCO's shipboard guidelines as the industry's mostly voluntary starting point. A follow up article that year, written after a cyberattack shut down operations at Belgian port operator SEA-Invest for days, argued that many ships carry devices and systems unknown even to their own operators, and that crews are rarely trained to spot phishing or manage network access.
Mandatory technical requirements in the form of International Association of Classification Societies (IACS) Unified Requirements have started to arrive, though they remain narrow. IACS UR E26 (Cyber Resilience of Ships) and IACS UR E27 (Cyber Resilience of On-Board Systems and Equipment) took effect on July 1, 2024.
- Both E26 and E27 apply to new ships contracted for construction on or after July 1, 2024, and classed by IACS member societies at over 500 gross tonnage on international voyages.
- E26 covers the ship as a whole.
- E27 targets the third-party systems, radar, engine control and cargo management that shipbuilders integrate but rarely design with cybersecurity as a requirement.
- Existing vessels already at sea, including tankers like the VL Prosperity and Vivit Africa LNG, aren't covered by either rule.
Port facilities have been under cyber-specific federal guidance longer, through Coast Guard guidance to MTSA-regulated facilities, and their binding deadline has now arrived as well. The Coast Guard's baseline cybersecurity rule for the Marine Transportation System took effect July 16, 2025, following a run of ransomware incidents at U.S. ports, including the 2024 attack attributed to the Rhysida group that disrupted Port of Seattle operations for weeks. Our own March 2025 review of that rule covered what it requires: designated cybersecurity officers, incident response plans, regular risk assessments and documented security controls.
NERC CIP followed a similar arc in the power sector, moving from voluntary standards to mandatory compliance with enforcement behind it. Maritime started from a different place. IMO Resolution MSC.428(98) has required companies to address cyber risk in their safety management systems since the first Document of Compliance verification after January 1, 2021, but that obligation describes what to consider rather than what to install. E26, E27 and the Coast Guard rule are the first maritime requirements specific enough to audit against, and they are arriving unevenly across vessels, equipment and ports.
What Visibility Requires at Sea
None of the requirements above solves the specific problem the VL Prosperity boarding exposed: knowing, continuously, what's on a ship's network and how it's behaving, without needing to send a team aboard to find out. That capability has to work differently at sea than at a fixed facility. Crews aren't network administrators, and few ships can spare the time or connectivity for active scanning. Most importantly, propulsion and engine control systems can't be patched or rebooted mid-voyage the way an office server can. Monitoring has to be primarily passive, reading network traffic without touching the systems that generate it, and it often has to run on rugged hardware built for vibration, heat and salt air rather than a data center rack.
Connectivity shapes the architecture as much as the sensors do. A vessel underway can lose or degrade its satellite link for hours at a stretch, so a design that ships traffic ashore for analysis will have blind spots at exactly the times a vessel is hardest to reach. The requirement is that detection runs in full on board: sensors, analysis, asset inventory and alerting all resident on the vessel, with nothing ashore needed to decide whether traffic on the engineering network looks wrong. When bandwidth is available, the ship synchronizes to a central view, so a fleet security team can compare vessels, track open vulnerabilities and produce documentation when a class surveyor or a port state inspector asks for it. When bandwidth is not available, the vessel keeps monitoring itself and the record is intact when the link returns.
A Hybrid OT Security Platform for Connected and Disconnected Ships
Nozomi Networks is the only OT security vendor with a hybrid platform that can be run on the cloud but can be reverted to completely on-premises operation. The same detection, asset inventory and analysis run on board whether or not the vessel can reach shore, so fully disconnected or air-gapped deployments are possible, even in projects where the rest of the infrastructure is cloud connected. For a fleet operator, that means one platform covering connected ships, disconnected ships, terminals, and the shore-side operations center, instead of a cloud product for the office and something separate for the hulls. We have deployed monitoring technology on approximately 1,000 vessels to date, extending the same asset visibility and threat detection used at pipelines and refineries onto the ships between them.
The VL Prosperity will eventually be cleared, or it won't, and the investigation will run its course independent of what any vendor has to say about it. What won't resolve on its own is the underlying gap: a global fleet of vessels carrying energy, chemicals and cargo across oceans with less network visibility than the terminals they load from and the refineries they supply. E26 and E27 will help for new construction over the coming decade, and Nozomi Networks is ready now to support the ships already on the water today.





