ICS / OT INCIDENT · MARITIME

One Port, Two Tankers, One LNG Carrier

In eight weeks a U.S. port authority lost its IT, two U.S.-bound tankers were boarded over cyber intrusions, and an LNG carrier lost its cargo monitoring off Italy. Laid end to end, the summer of 2026 shows the business network on ships and terminals is a working route to the systems that move cargo.

Matt Lucas  |  October 6, 2026  |  8 min
Editorial hero illustration
TL;DR
  • What: In one summer, a U.S. port authority lost its IT systems, two U.S.-bound tankers were boarded by the Coast Guard and FBI over cyber intrusions, and an LNG carrier lost its cargo monitoring off Italy. On October 2, Bloomberg reported that investigators found evidence the VL Prosperity's propulsion system had been accessed.
  • Impact: U.S. authorities are now watching close to 20 vessels worldwide for cyber threats and ask for advance notice before those ships enter a U.S. port. No disruption to navigation, crew safety or the environment has been reported, and no attacker has been publicly named.
  • Fix: Treat ships and terminals as OT that has to be watched where it sits. RedEye assesses the paths from the business network and the satellite link into machinery and terminal systems, and leaves Caver in place to watch them, including the radio spectrum around the hull.
  • Who: Port authorities and terminal operators, owners, managers and charterers of tankers and gas carriers trading with the U.S., and every MTSA-regulated facility working toward the Coast Guard's July 2027 cyber plan deadline.

Taken one at a time, each of this summer's maritime incidents reads like a local story. A port in North Carolina switches to manual gates. A tanker off Texas gets an unusual boarding. An LNG carrier sits off the Italian coast and then leaves without discharging. Put them on one timeline and they describe something larger: in roughly eight weeks, the industry learned that the business network on a ship or a terminal is a working route to the systems that move cargo and steer hulls.

This post lays the season out in order, separates what investigators have confirmed from what has only been claimed, and looks at what it means for the operators the Coast Guard's cyber rule now covers.

The season, in order

Aug 1The crude carrier VL Prosperity, 1,093 feet and Liberian-flagged, departs Egypt's Sidi Kerir terminal for Galveston, Texas.
Aug 4The North Carolina State Ports Authority detects an intrusion. IT systems go down at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port.
Aug 5All three facilities open late, at 8 a.m., and process trucks by hand while IT recovers. The authority calls the breach contained and works with the Coast Guard and state agencies.
Aug 7The date Iranian state media later gives for an attack on the VL Prosperity near the Strait of Gibraltar.
Aug 20Iran's Mehr News Agency claims hackers reached the tanker's engine room, slowed engine cooling flow, raised engine speed, interfered with fuel systems and cut communications for about 30 hours.
Aug 21A joint team of Coast Guard law enforcement, marine inspectors, a Cyber Protection Team and FBI Cyber Action Team operators boards the VL Prosperity in the Gulf of Mexico.
Aug 24A second U.S.-bound tanker is boarded for the same reason. It has not been publicly named.
Early SeptThe LNG carrier Vivit Africa loses access to systems that monitor cargo parameters off Italy. The crew suspects a cyberattack; the Italian Coast Guard describes a malfunction. The ship later sails without discharging.
Sept 17Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, confirms investigators found malicious cyber activity aboard.
Oct 2Bloomberg reports FBI and Coast Guard investigators found evidence the VL Prosperity's propulsion system was accessed, and that close to 20 vessels are now monitored.

What is confirmed, and what is only claimed

The details that travel furthest are the least supported. Here is the split, as of today.

Confirmed by U.S. officials or the operatorClaimed, unverified, or disputed
Malicious cyber activity was found aboard the VL Prosperity, and investigators found evidence its propulsion system was accessed.That attackers changed cooling flow, engine speed and fuel delivery. This comes from Iranian state media citing an unnamed crew member.
Two U.S.-bound tankers were boarded, on August 21 and 24.Who did it. The Coast Guard has not publicly attributed the intrusions to Iran or anyone else.
No operational disruption, vessel instability, danger to crews or environmental impact was found.That the Vivit Africa was attacked at all. The crew suspected it; Italian authorities called it a malfunction.
NC Ports lost IT systems at three facilities and ran gates by hand while it recovered.Whether data left NC Ports. The authority has not said, and no group has been named.
Close to 20 vessels are being monitored, and the Coast Guard asks for advance notice of their U.S. port calls.How long any attacker kept access, and what they could actually control.

The pattern: the business network is the way in

None of these incidents needed anyone to board a ship or break into a control room. The route the Coast Guard describes is ordinary IT that happens to share a path with machinery. "The real thing we're concerned about is those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel," Rear Adm. Grable told CBS News. Asked how advanced the attackers were, she said: "Not necessarily that sophisticated. There is malicious source code that people can get their hands on."

That is the uncomfortable part. A ship is an industrial plant that moves, runs on a satellite link and spends most of its life out of reach of anyone who could respond. A terminal is an industrial plant whose terminal operating system decides where every container goes. In both, the systems that matter most sit one or two hops from email, crew Wi-Fi and vendor remote access.

The port and the ship also fail differently. When NC Ports lost IT, trucks still moved, slowly, by hand, with staff on site. A ship that loses communications for 30 hours has no help desk and no one coming. The consequence the Coast Guard named is not a breach notice: it is "a vessel blocking a waterway or a pollution incident."

The rule that applies, and the ships it does not reach

The Coast Guard's final rule on cybersecurity in the Marine Transportation System, 33 CFR Part 101 Subpart F, took effect on July 16, 2025. It applies to U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities regulated under the Maritime Transportation Security Act. Its milestones:

Read that list against this summer. A port authority like NC Ports is the kind of MTSA facility the rule was written for, and its July 2027 plan now has a real incident to answer to. The tankers are a different story. The VL Prosperity and the Vivit Africa are Liberian-flagged, so the rule does not reach them directly. What reaches them is what the U.S. did in practice: boarding at sea and asking for notice before port calls. For foreign-flagged ships, Port State Control is where cyber now shows up.

What watching these systems actually looks for

The incidents point at a short list of things worth detecting, on a ship or at a terminal:

How RedEye approaches it

RedEye starts with an assessment of the paths from the business network, the satellite link and vendor access into the systems that move cargo and steer the hull, then leaves Caver in place to watch them. On a ship, Caver runs aboard as a sealed install that keeps working when the link drops, decodes the industrial protocols on the machinery network, listens to the spectrum around the hull, and takes threat intelligence as signed bundles small enough for satcom. At a terminal, it ties IT, identity and OT activity together, so an admin change and a controller write show up as one story. It reports against the frameworks operators already answer to, including the Coast Guard rule.

This summer's tankers came through without harm to their crews or the water. The point of the season is that nobody can yet say how close any of them came, and the next one may not announce itself on a state news agency.

Sources: Bloomberg, Insurance Journal, CBS News, SecurityWeek, Holland & Knight, BleepingComputer, WECT, Federal Register, 33 CFR 101 Subpart F. Earlier RedEye coverage: the VL Prosperity and the Vivit Africa.

Find the path before someone else uses it

RedEye assesses the routes from the business network, the satellite link and vendor access into the systems that move cargo and steer the hull, then leaves Caver in place to watch them, on the vessel or at the terminal. Ports, terminals, owners, managers and charterers: talk to us.

Talk to us about maritime OT

Sources: Bloomberg, October 2, 2026; CBS News; CBS News, September 16, 2026; TechCrunch, September 18, 2026; Federal Register, Cybersecurity in the Marine Transportation System. Attribution of the VL Prosperity intrusion is unconfirmed by U.S. authorities as of publication.