FBI and Coast Guard boarded two hacked tankers at sea
The FBI and Coast Guard boarded two US-bound tankers in the Gulf of Mexico in August after indications that both vessels' networks had been compromised.

Two oil tankers heading for the United States were boarded at sea by the FBI and the US Coast Guard in August, after indications that the networks of both vessels had been compromised. The boardings took place in the Gulf of Mexico between 21 and 24 August, and three weeks on nobody has been named.
Shipping has spent years being told it is the next soft target. This is one of the few times the response has been physical: armed federal teams climbing a rope ladder onto a working tanker to inspect its computers.
What the agencies actually did
A joint statement from the FBI and the Coast Guard, shared with reporters, said the teams boarded the vessels “to ensure integrity of the vessel's operational and information technology systems following indications that the networks of both vessels were compromised”. A Coast Guard spokesperson went further with Cybernews, describing a team made up of Coast Guard law enforcement personnel, members of a Coast Guard Cyber Protection Team, a vessel inspector and FBI Cyber Action Team operators. The statement said the captain, the crew and the owner's shore-side staff cooperated, and that there were “no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts”.
One of the ships has a name
The Coast Guard would not name the vessels involved, and a spokesperson offered nothing beyond the emailed statement. TechCrunch reports that CBS News confirmed one of the tankers is VL Prosperity, a 333-metre Liberian-flagged crude carrier able to hold more than two million barrels of oil. TechRadar reports the ship was sailing from Egypt's Sidi Kerir oil terminal towards Galveston, Texas, where it was due on 24 August, and that it asked for law enforcement help three days before it was due to dock. A second vessel, reported as Kohaku, was also caught up in the incident.
Nobody has claimed it, everyone is guessing
No group has publicly taken responsibility and neither agency has attributed the intrusion. CBS News, cited by TechCrunch, reported that Iranian media said hackers interfered with the ship's speed and fuel systems and that the vessel lost communications for more than a day, and that American officials are looking at whether Iran was responsible. TechRadar notes that Iran's Mehr News Agency framed the attack as a message from the country's “Resistance Front”. That is a claim from a state-aligned outlet, not a finding, and it should be read that way.
Why this one matters
Tankers are small floating networks: navigation, cargo management, fuel systems, comms and crew services all run over kit that was never designed to be defended. The reason this case stands out is the overlap of three things. The target was critical infrastructure on the move, the reported access reached beyond the office side of the ship into propulsion and cargo, and the response escalated from a helpdesk to federal agents boarding a vessel at sea. TechCrunch points out that Iranian-linked hackers have hit a medical device maker, Los Angeles mass transit and more than a hundred US water facilities in recent months, with CISA calling those attacks opportunistic. Opportunistic is not the same as harmless when the thing being opportunistically attacked is a loaded tanker.
Our opinion
The most interesting sentence in all of this is the one about there being no reports of operational disruption, because it tells you how the boarding was sold. Two tankers, one hacked badly enough that the crew called for help three days out of port, and the official line is that nothing went wrong and everyone cooperated — which is exactly what you would say if you had found something worth investigating and no appetite for telling the shipping industry how close it came. What the case really exposes is that a ship at sea has no patching window. You cannot roll a maintenance slot into a 25-day crossing, you cannot swap out the navigation stack at anchor, and you certainly cannot plug a compromised network into a support queue. The only escalation path left is people, and people have to arrive by boat. Until shipping gets a credible answer for updating systems it cannot take offline, the response to a hacked tanker will keep looking like a boarding party rather than a fix.