- What: In one summer, a U.S. port authority lost its IT systems, two U.S.-bound tankers were boarded by the Coast Guard and FBI over cyber intrusions, and an LNG carrier lost its cargo monitoring off Italy. On October 2, Bloomberg reported that investigators found evidence the VL Prosperity's propulsion system had been accessed.
- Impact: U.S. authorities are now watching close to 20 vessels worldwide for cyber threats and ask for advance notice before those ships enter a U.S. port. No disruption to navigation, crew safety or the environment has been reported, and no attacker has been publicly named.
- Fix: Treat ships and terminals as OT that has to be watched where it sits. RedEye assesses the paths from the business network and the satellite link into machinery and terminal systems, and leaves Caver in place to watch them, including the radio spectrum around the hull.
- Who: Port authorities and terminal operators, owners, managers and charterers of tankers and gas carriers trading with the U.S., and every MTSA-regulated facility working toward the Coast Guard's July 2027 cyber plan deadline.
Taken one at a time, each of this summer's maritime incidents reads like a local story. A port in North Carolina switches to manual gates. A tanker off Texas gets an unusual boarding. An LNG carrier sits off the Italian coast and then leaves without discharging. Put them on one timeline and they describe something larger: in roughly eight weeks, the industry learned that the business network on a ship or a terminal is a working route to the systems that move cargo and steer hulls.
This post lays the season out in order, separates what investigators have confirmed from what has only been claimed, and looks at what it means for the operators the Coast Guard's cyber rule now covers.
The season, in order
| Aug 1 | The crude carrier VL Prosperity, 1,093 feet and Liberian-flagged, departs Egypt's Sidi Kerir terminal for Galveston, Texas. |
| Aug 4 | The North Carolina State Ports Authority detects an intrusion. IT systems go down at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. |
| Aug 5 | All three facilities open late, at 8 a.m., and process trucks by hand while IT recovers. The authority calls the breach contained and works with the Coast Guard and state agencies. |
| Aug 7 | The date Iranian state media later gives for an attack on the VL Prosperity near the Strait of Gibraltar. |
| Aug 20 | Iran's Mehr News Agency claims hackers reached the tanker's engine room, slowed engine cooling flow, raised engine speed, interfered with fuel systems and cut communications for about 30 hours. |
| Aug 21 | A joint team of Coast Guard law enforcement, marine inspectors, a Cyber Protection Team and FBI Cyber Action Team operators boards the VL Prosperity in the Gulf of Mexico. |
| Aug 24 | A second U.S.-bound tanker is boarded for the same reason. It has not been publicly named. |
| Early Sept | The LNG carrier Vivit Africa loses access to systems that monitor cargo parameters off Italy. The crew suspects a cyberattack; the Italian Coast Guard describes a malfunction. The ship later sails without discharging. |
| Sept 17 | Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, confirms investigators found malicious cyber activity aboard. |
| Oct 2 | Bloomberg reports FBI and Coast Guard investigators found evidence the VL Prosperity's propulsion system was accessed, and that close to 20 vessels are now monitored. |
What is confirmed, and what is only claimed
The details that travel furthest are the least supported. Here is the split, as of today.
| Confirmed by U.S. officials or the operator | Claimed, unverified, or disputed |
|---|---|
| Malicious cyber activity was found aboard the VL Prosperity, and investigators found evidence its propulsion system was accessed. | That attackers changed cooling flow, engine speed and fuel delivery. This comes from Iranian state media citing an unnamed crew member. |
| Two U.S.-bound tankers were boarded, on August 21 and 24. | Who did it. The Coast Guard has not publicly attributed the intrusions to Iran or anyone else. |
| No operational disruption, vessel instability, danger to crews or environmental impact was found. | That the Vivit Africa was attacked at all. The crew suspected it; Italian authorities called it a malfunction. |
| NC Ports lost IT systems at three facilities and ran gates by hand while it recovered. | Whether data left NC Ports. The authority has not said, and no group has been named. |
| Close to 20 vessels are being monitored, and the Coast Guard asks for advance notice of their U.S. port calls. | How long any attacker kept access, and what they could actually control. |
The pattern: the business network is the way in
None of these incidents needed anyone to board a ship or break into a control room. The route the Coast Guard describes is ordinary IT that happens to share a path with machinery. "The real thing we're concerned about is those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel," Rear Adm. Grable told CBS News. Asked how advanced the attackers were, she said: "Not necessarily that sophisticated. There is malicious source code that people can get their hands on."
That is the uncomfortable part. A ship is an industrial plant that moves, runs on a satellite link and spends most of its life out of reach of anyone who could respond. A terminal is an industrial plant whose terminal operating system decides where every container goes. In both, the systems that matter most sit one or two hops from email, crew Wi-Fi and vendor remote access.
The port and the ship also fail differently. When NC Ports lost IT, trucks still moved, slowly, by hand, with staff on site. A ship that loses communications for 30 hours has no help desk and no one coming. The consequence the Coast Guard named is not a breach notice: it is "a vessel blocking a waterway or a pollution incident."
The rule that applies, and the ships it does not reach
The Coast Guard's final rule on cybersecurity in the Marine Transportation System, 33 CFR Part 101 Subpart F, took effect on July 16, 2025. It applies to U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities regulated under the Maritime Transportation Security Act. Its milestones:
- Since July 16, 2025: reportable cyber incidents go to the National Response Center.
- By January 12, 2026: cybersecurity training for personnel, then yearly.
- By July 16, 2027: a designated Cybersecurity Officer, a completed Cybersecurity Assessment, and a submitted Cybersecurity Plan.
Read that list against this summer. A port authority like NC Ports is the kind of MTSA facility the rule was written for, and its July 2027 plan now has a real incident to answer to. The tankers are a different story. The VL Prosperity and the Vivit Africa are Liberian-flagged, so the rule does not reach them directly. What reaches them is what the U.S. did in practice: boarding at sea and asking for notice before port calls. For foreign-flagged ships, Port State Control is where cyber now shows up.
What watching these systems actually looks for
The incidents point at a short list of things worth detecting, on a ship or at a terminal:
- The satellite terminal and remote access. Management logins to the terminal itself, vendor sessions at odd hours, and new destinations crossing a link that normally talks to a handful of services.
- Business-to-control crossings. A host on the business side starting to talk to engine, cargo or ballast controllers. A new admin grant followed by a write to a controller is the sequence to alarm on.
- Machinery behaviour. Setpoint and speed changes that do not match the voyage plan, and writes from a host that has never written before.
- Silence as a signal. A communications blackout is an event, not an absence of data. So is a sensor or log source that stops reporting.
- The spectrum. GNSS jamming and spoofing, a rogue access point, a radio that was not aboard at the last port, a drone on approach. Network sensors cannot see any of it.
- Terminal operations. Changes to who can reach the terminal operating system, and the gate and container workflows it drives.
How RedEye approaches it
RedEye starts with an assessment of the paths from the business network, the satellite link and vendor access into the systems that move cargo and steer the hull, then leaves Caver in place to watch them. On a ship, Caver runs aboard as a sealed install that keeps working when the link drops, decodes the industrial protocols on the machinery network, listens to the spectrum around the hull, and takes threat intelligence as signed bundles small enough for satcom. At a terminal, it ties IT, identity and OT activity together, so an admin change and a controller write show up as one story. It reports against the frameworks operators already answer to, including the Coast Guard rule.
This summer's tankers came through without harm to their crews or the water. The point of the season is that nobody can yet say how close any of them came, and the next one may not announce itself on a state news agency.
Sources: Bloomberg, Insurance Journal, CBS News, SecurityWeek, Holland & Knight, BleepingComputer, WECT, Federal Register, 33 CFR 101 Subpart F. Earlier RedEye coverage: the VL Prosperity and the Vivit Africa.
