U.S. Investigates Cyber Incidents on Two Oil Tankers

FBI & Coast Guard Board Oil Tankers After Network Compromises

MEDIUM
September 20, 2026
4m read
CyberattackIndustrial Control SystemsThreat Intelligence

Related Entities

Organizations

Other

Black Kite

Full Report

Executive Summary

Between August 21 and 24, 2026, a joint team of cybersecurity personnel from the U.S. Coast Guard and the FBI boarded two oil tankers in the Gulf of Mexico that were en route to the United States. The boardings were initiated in response to reports that the vessels' onboard computer networks had been compromised. One of the initial reports was particularly alarming, suggesting that the intrusion had interfered with the ship's navigation, propulsion, and cargo systems. However, after investigating, the agencies confirmed that the incidents resulted in no operational disruptions, safety impacts, or environmental damage. The source of the attacks has not been attributed.

Threat Overview

This incident underscores the vulnerability of the maritime sector, a critical component of global trade and energy supply chains, to cyberattacks.

  • Target: Two U.S.-bound oil tankers.
  • Location: Gulf of Mexico.
  • Event: Suspected network compromise on both vessels.
  • Alleged Impact: Initial reports for one tanker claimed interference with critical Operational Technology (OT) systems, including navigation (potentially the Electronic Chart Display and Information System - ECDIS), propulsion, and cargo management.
  • Official Finding: Authorities found no evidence of operational or safety impact.

There is a significant gap between the initial dramatic report and the official findings. This could be due to several reasons: the initial report was inaccurate, the crew successfully mitigated the issue before the boarding, or the intrusion was real but less impactful than feared. Regardless, the fact that a cyber incident on a tanker prompted a joint FBI-Coast Guard response indicates the seriousness with which U.S. authorities view threats to maritime OT.

Technical Analysis

Attacking maritime OT systems is a specialized field. Based on the systems allegedly targeted, potential attack vectors could include:

  • Satellite Communications (SATCOM): Ship-to-shore communication systems are a primary link to the outside world and a known target for attackers. (T0884 - Connection through Transmitted Media)
  • Phishing: Targeting crew members with phishing emails to gain access to the ship's business network (IT), then pivoting to the operational networks (OT). (T1566 - Phishing)
  • Removable Media: Use of infected USB drives by crew or maintenance personnel. (T1200 - Hardware Additions)
  • Lack of Segmentation: A common issue on vessels is a flat network where IT and OT systems are not properly isolated, allowing an attacker to move from a compromised email account to the ship's navigation system. (M1030 - Network Segmentation)

Impact Assessment

While the official assessment found no impact in this case, a successful attack on a tanker's OT systems could be catastrophic.

  • Safety: Manipulation of navigation systems could lead to collisions or grounding. Interference with propulsion or steering could cause a loss of control.
  • Environmental: A collision or grounding could result in a major oil spill, causing massive environmental and economic damage.
  • Economic: Disruption of cargo systems could prevent loading/unloading, while an attack on propulsion could disable the vessel, disrupting supply chains and incurring significant financial losses.

This incident also comes amid reports of a nearly 40% increase in ransomware attacks against the manufacturing sector, indicating a broader trend of attackers targeting OT environments.

Cyber Observables — Hunting Hints

For maritime security teams, hunting for such threats involves looking for anomalies in both IT and OT environments:

Type
Log Source
Value
Vessel Information and Communication Technology (ICT) logs
Description
Look for unexpected remote connections or traffic to/from unusual IP addresses.
Type
Network Traffic Pattern
Value
IT-to-OT network traffic
Description
Any traffic crossing the IT/OT boundary that is not explicitly allowed and expected should be investigated.
Type
Process Name
Value
Unauthorized software on ECDIS or other OT workstations
Description
The presence of non-standard software on critical navigation or engineering systems is a major red flag.

Detection & Response

  • Network Segmentation: The most critical defense. Use firewalls to create a strong, monitored boundary between the ship's IT and OT networks. All traffic crossing this boundary should be logged and inspected.
  • OT-Specific Monitoring: Deploy network monitoring solutions capable of understanding OT protocols (e.g., Modbus, NMEA 0183) to detect anomalous commands or values being sent to physical controllers.
  • Crew Training: Train crew members on cybersecurity best practices, including identifying phishing emails and proper use of removable media.

Mitigation

  • Harden OT Systems: Change default passwords, disable unused ports and services, and restrict software installation on all OT workstations and devices.
  • Resilient Navigation: Ensure the vessel has and practices using non-digital navigation methods (e.g., paper charts, celestial navigation) as a backup in case of GPS or ECDIS failure/compromise.
  • Incident Response Plan: Develop and drill a specific incident response plan for OT-related cyber incidents that includes the crew, onshore technical staff, and relevant authorities like the Coast Guard.

Timeline of Events

1
August 21, 2026
Start of the period during which the FBI and Coast Guard boarded two oil tankers.
2
August 24, 2026
End of the period during which the FBI and Coast Guard boarded two oil tankers.
3
September 19, 2026
The incident was reported in daily OT security news.
4
September 20, 2026
This article was published

MITRE ATT&CK Mitigations

The most critical mitigation in a maritime environment is to strictly segment the vessel's Operational Technology (OT) network from its Information Technology (IT) network.

Train crew members to be vigilant against phishing and to follow proper cybersecurity hygiene, as they are the first line of defense.

Crew should be trained to cross-reference digital readouts (e.g., from ECDIS) with physical instruments and visual checks to detect manipulation of view.

Timeline of Events

1
August 21, 2026

Start of the period during which the FBI and Coast Guard boarded two oil tankers.

2
August 24, 2026

End of the period during which the FBI and Coast Guard boarded two oil tankers.

3
September 19, 2026

The incident was reported in daily OT security news.

Sources & References

Daily OT Security News: September 19, 2026
Security Boulevard (securityboulevard.com) September 19, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Maritime SecurityICSOTCritical InfrastructureFBIUS Coast GuardOil Tanker

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.