U.S. Investigates Cyberattacks On America-Bound Energy Tankers

The U.S. Coast Guard and Federal Bureau of Investigation are examining cyberattacks involving energy tankers headed toward American ports, according to CBS.

U.S. authorities boarded a foreign-flagged, Texas-bound oil tanker on August 21 after receiving indications that overseas attackers had compromised its onboard network.

A separate report indicated that at least two vessels carrying oil or liquefied natural gas were affected. The incidents reportedly began near the Strait of Gibraltar before the ships continued toward the Gulf of Mexico.

Officials have not publicly identified the attackers or disclosed the specific systems that were compromised. The investigation is examining whether the incidents represented isolated intrusions or part of a broader campaign targeting energy transportation.

Modern commercial vessels depend on interconnected digital systems for navigation, propulsion, communications, cargo monitoring and port operations. Compromising those networks could disrupt a ship’s voyage or interfere with systems needed to operate safely.

The most serious scenarios could include collisions, groundings, explosions or oil spills. Even a less destructive intrusion could delay deliveries, increase insurance costs and require a vessel to remain out of service while security teams inspect and rebuild its networks.

Energy tankers are particularly sensitive targets because they transport valuable and potentially hazardous cargo. Attacks against them could also contribute to volatility in oil and natural-gas markets if shipping companies avoid certain routes or ports.

The investigation comes during a period of heightened geopolitical tension affecting global energy transportation. Ships already face physical threats around important waterways, including the Strait of Hormuz and Bab al-Mandeb.

Cyberattacks create an additional layer of risk because perpetrators may be able to operate remotely and conceal their identities. Governments, criminal organizations and politically motivated groups can use similar tools, making attribution difficult.

Shipping companies have increased their reliance on connected technology to improve efficiency and monitor fleets. Those systems can create vulnerabilities when older operational equipment is connected to modern networks without adequate security protections.

The Coast Guard has expanded its cybersecurity guidance for the maritime industry, and vessel operators are expected to report incidents affecting safety or critical operations. However, cybersecurity practices can vary across ships, owners, flags and jurisdictions.

The investigation may lead to new recommendations involving network segmentation, access controls, software updates and incident-response planning. It could also increase pressure on vessel owners to treat cyber protection as a core safety requirement rather than only an information-technology concern.

For energy companies and commodity traders, the incidents demonstrate that supply-chain risk extends beyond pipelines, refineries and physical shipping lanes. A successful digital attack on vessel operations could interrupt energy deliveries even when production facilities and ports remain functional.