- What: FBI and U.S. Coast Guard investigators found evidence that hackers accessed the propulsion system of the supertanker VL Prosperity as it approached the Texas coast this summer, Bloomberg reported on October 2. Communications, navigation, cargo, engine-room, fuel and lube-oil systems were all reported affected.
- Impact: U.S. authorities have stepped up monitoring of nearly 20 other vessels worldwide and now ask for advance notice before those ships reach U.S. ports. How long the access lasted, what could be controlled, and who did it are still under investigation.
- Fix: Put the monitoring aboard. Caver watches the satellite terminal, the traffic crossing it, the machinery control network and the radio spectrum around the hull, from a sealed install that keeps working when the link drops and takes its threat intelligence as signed bundles sized for satcom.
- Who: Owners, managers and charterers of tankers and gas carriers bound for U.S. ports, the terminals that receive them, and any fleet that runs propulsion and navigation behind a single firewall on a satellite link.
Somebody got into the engine room of a 333-meter supertanker carrying about 2.3 million barrels of crude toward Galveston. They did not need to board it. According to Bloomberg, FBI and Coast Guard investigators found evidence that hackers accessed the propulsion system of the VL Prosperity as it approached the Texas coast this summer. Since then, U.S. authorities have stepped up monitoring of nearly 20 other vessels around the world and now ask for advance notice before those ships reach U.S. ports.
That last detail is the one every fleet operator should sit with. The United States is now treating a class of merchant ships as possible carriers of somebody else's access, and it is asking them to announce themselves before they arrive.
What was reported
The VL Prosperity is a Liberian-flagged crude carrier managed by HMM Ocean Service of South Korea. CBS News reported that it was bound for Galveston from Egypt's Sidi Kerir terminal by way of Gibraltar when it lost communications on August 7. Iran's Mehr News reported the incident on August 20. On August 21 the Coast Guard and the FBI boarded the ship, with a USCG Cyber Protection Team and an FBI Cyber Action Team aboard, and on September 16 the Coast Guard confirmed the details publicly.
The systems reported affected read like a ship's whole machinery space: propulsion, navigation, cargo, communications, the engine room, and the fuel and lube-oil systems. Communications were reportedly lost for 30 hours. TechCrunch reported that two vessels were boarded in the Gulf of Mexico and that U.S. investigators are examining whether Iranian-backed hackers were responsible.
No U.S. agency has attributed the intrusion. Iranian state media claimed it, under the Tasnim headline "No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?" Quinton DuBose, a former Coast Guard cyber official, cautioned CBS that Iranian-linked actors are often quick to oversell their cyber influence. We are not attributing it either. Bloomberg reports that officials are still examining how it happened and who did it, and that how long the access lasted and what the intruders could control is not yet clear.
Rear Adm. Amy Grable, commander of Coast Guard Cyber Command, told CBS News that a cyberattack on a vessel could mean "a vessel blocking a waterway or a pollution incident or any other number of safety and security hazards to our ports and waterways," and that "$5.4 trillion in commerce flows through U.S. ports annually." A loaded VLCC that cannot hold its speed or its heading in a ship channel is not an IT incident. It is a closed port.
Why ships are uniquely exposed
We wrote two weeks ago, about the Vivit Africa, that a ship is an isolated plant until it docks. The VL Prosperity shows the other half: a modern ship is never fully isolated at all. Every condition that makes an industrial plant hard to defend is present aboard, and several are worse.
- An always-on satellite link. VSAT and low-earth-orbit broadband give the ship the internet at sea. They also give the internet the ship, every hour of every voyage, through a terminal whose own management interface is often the least-watched device aboard.
- Flat networks. CBS reported investigators' concern that many ships rely on a single firewall between satellite internet and critical systems, with navigation, propulsion, ballast and steering on one shared network.
- Decades-old OT. Engine and cargo automation is specified at the yard and runs for the life of the hull. Protocols designed for trusted serial links now ride Ethernet next to the crew's phones.
- Crew devices. Twenty-odd people live aboard for months, with phones, laptops and USB sticks that touch the same link and, too often, the same switches.
- Vendor remote access. Engine, automation and navigation makers sell remote diagnostics over that satellite link. Each one is a standing path from shore into the machinery network.
- Long dwell at sea. A tanker can be weeks between ports. An intruder who gets in at Sidi Kerir has the whole Mediterranean and the Atlantic before anyone with a laptop comes aboard.
- No SOC aboard. The crew are mariners. Nobody on watch is reading firewall logs, and the shore team sees only what the link carries, when it carries it.
Grable's own assessment of the barrier to entry was blunt: "Not necessarily that sophisticated," with artificial intelligence "accelerating the rate at which we need to take action." The tools to find the weak satellite terminal or the forgotten remote-service account are getting faster. The ships are not getting newer.
What an attacker does with a ship
DuBose's framing to CBS is the right one for defenders: the realistic goal is not a Hollywood remote hijack but "what systems can I disrupt to the point where it affects the safe handling and makes the ship less safe to operate." On a tanker that list is short and ugly: engine speed and fuel, the lube-oil system that keeps the main engine alive, ballast, steering, cargo monitoring, and the navigation picture the bridge relies on. Take communications away at the same time and the master cannot even ask the shore what the systems are doing. Spoof the satellite positioning and the bridge and the shore stop agreeing on where the ship is.
The attack does not have to come down the cable, either. A ship at anchor or alongside is surrounded by radio: launches, pilot boats, other ships, the terminal, a drone over the deck, a rogue cell or Wi-Fi access point brought aboard in someone's bag. The defenders who only look at the firewall are watching one door of a building with a dozen.
How Caver defends a ship, layer by layer
Caver is RedEye's security analytics platform, and its maritime edition is built for exactly this vessel: one that has to watch itself at sea and report home when it can. Everything below is in the product today.
Ship to shore: the satellite link and everything crossing it
Caver Maritime ships detections for the terminal: its management page reached over cleartext HTTP, telnet or FTP sessions to it, and scripted user-enumeration probing of its web interface. These are the weaknesses previously found exposed from the internet on fleet VSAT terminals.
Every remote-support path into the ship is a session Caver sees on the wire and on the host: RDP or VNC arriving from outside the ship, remote-support tools such as ScreenConnect, BeyondTrust, AnyDesk and TeamViewer starting a session, an RMM relay carrying traffic into the machinery network, a session from somewhere the vendor has never connected from, and a session that is followed by a new service or a privilege change. The engine maker's diagnostics window should be the most visible event of the voyage, not the quietest.
NetFlow v5 and v9, IPFIX, sFlow and Suricata EVE all land in the same lake, so every connection that crosses the link, inbound or outbound, is evidence the ship keeps, not a counter on a router.
In sealed mode Caver refuses every outbound connection outside an explicit allowlist. The security platform aboard never becomes one more thing talking to the internet.
A fleet and shore SOC board puts every vessel on one screen: sensor count, last port call, how stale each ship's stream is. Shore knows which ship has gone quiet before the master calls.
Ship to ship: what comes alongside
Caver decodes AIS position and static voyage reports into vessel identity: MMSI, name, call sign, destination and flag. The ship builds its own inventory of who is around it, joined to everything else it hears.
Caver takes a census of every emitter aboard at departure and flags anything first heard after the last port stop: whatever came aboard from a launch, a pilot boat or a ship-to-ship transfer is on the list within the hour.
A strong cellular emitter first heard at sea that is not a phone has the shape of an IMSI catcher, because offshore there is no legitimate tower in range. A second radio advertising the ship's own network name is an evil twin. Caver alarms on both.
Caver compares the ship's GNSS position track with its AIS own-ship track. When one says the ship is moving and the other says it is not, that disagreement is itself a detection, because it is how GNSS and AIS spoofing first show.
The control network: propulsion, fuel, cargo
The Caver collector decodes industrial protocols byte by byte from a passive tap: Modbus TCP, DNP3, BACnet, IEC 60870-5-104, EtherNet/IP and CIP, S7comm, OPC UA, IEC 61850 GOOSE and PROFINET. Every read, write and device on the machinery network becomes a record, and nothing is ever sent to a controller.
Caver scores its detection coverage against MITRE ATT&CK for ICS and maps the cross-domain paths: rules whose techniques cross from the enterprise matrix into the ICS matrix. That is the exact path the single firewall is supposed to stop, watched on both sides.
A sensor or comms link toggling inside its own alarm limits raises no alarm and quietly corrupts the loop paced off it: a pump short-cycles, a valve hunts. Caver finds those flapping points and slow drifts, the band where tampering and failing equipment both hide.
Caver's compliance reports grade the decoded OT estate against IEC 62443 requirements and the Coast Guard rule, control by control, with the query behind every grade.
The spectrum: drones, rogue emitters, jamming and spoofing
Caver flags a drone controller first heard aboard within the hour, and a drone closing on the ship: three or more direction-finding hits with range falling and the closest estimate inside 500 meters, carrying the bearing from the bow. A controller on the bridge or in the engine room trips a restricted-zone rule on its own.
A GNSS noise floor 10 dB above the sensor's own baseline, the same rise on two sensors at once, and a strong coherent L1 carrier arriving with a position jump: interference, corroborated jamming and spoofing are three separate detections. Wideband jamming across several bands at once is a fourth.
Every emitter aboard resolves to an identity built from three layers: MAC and vendor OUI, self-announced serial or ID, and its radio-level fingerprint. Captured with rtl_433, rtl_power sweeps and Kismet, from commodity software-defined radios.
Personal-device bands are counted, never identified or joined to a crew member. The maritime boards report emitters by fingerprint and count, so a flag state's or a crew's privacy question has a written answer.
Threat intelligence and fingerprinting
RedEye's RF feed carries the fingerprints of known jammers, IMSI catchers, drone controllers, rogue access points and GNSS spoofers as STIX indicators. One match aboard is the alarm. A watchlisted vendor OUI adds to the device's risk score instead, because a vendor is a reason to look, not a verdict.
Shore exports the fingerprint set as a signed bundle; the ship verifies the signature, refuses a rollback to an older version and refuses an expired one, and the detections pick it up within a minute. A tampered or stale update never reaches the rules.
Caver pulls RedEye's detection content from feeds.redeyesecurity.com over STIX 2.1 and TAXII 2.1, imports it as an offline bundle on a sealed install, and ingests CISA's Known Exploited Vulnerabilities catalog on schedule.
RF detections feed Caver's entity risk model, so a device that was new since port, then heard in the engine room, then matched a watchlisted vendor, rises as one story instead of three unrelated alerts.
Built to live aboard
Caver runs on the vessel, not in somebody's cloud. Events are normalized to OCSF, OpenTelemetry is a first-class input, and the lake is open Iceberg and Parquet that the operator owns. Caver stores raw events at a measured 48 to 1, so far more of the voyage fits on the hardware a ship already carries. When the link comes back, the shore gets the record, not a phone call.
Proven on a real hull
On September 27 we took Caver's maritime path to the Nashville riverfront, where USS LST 325, the World War II tank landing ship that now sails the rivers as a museum, was alongside. With one consumer software-defined radio, about $40 of hardware, and a whip antenna on a car roof, the collector decoded the ship's AIS identity at 300 feet and at 100 feet: name, call sign, destination and flag, assembled from the two-part static voyage report that carries a vessel's name. The capture now replays in Caver's test suite on every change, so the decode that worked on a real ship keeps working.
The rule that applies, and the ship it does not
The Coast Guard's maritime cybersecurity rule, 33 CFR part 101 subpart F, took effect on July 16, 2025. It covers U.S.-flagged vessels, Outer Continental Shelf facilities and facilities regulated under the Maritime Transportation Security Act. Cyber incidents have been reportable to the National Response Center since the effective date, and owners and operators must designate a Cybersecurity Officer, complete a Cybersecurity Assessment and submit a Cybersecurity Plan by July 16, 2027, under the schedule as published. The Coast Guard has sought comment on delaying implementation for U.S.-flagged vessels.
A Liberian-flagged tanker is not directly subject to that rule. The terminal it was bound for is. That is the gap the advance-notice request is quietly filling: the regulation reaches the dock, and the ships coming to it are being asked to account for themselves. Caver ships a USCG MTS report template keyed to the rule's own CFR section numbers, and a maritime compliance and fleet posture board that shows, per vessel, the monitoring evidence each ship holds and how recently it reported. A CySO preparing an assessment, and a terminal deciding what to ask of arriving ships, can work from evidence instead of attestation.
What operators should demand now
Whether or not your fleet is one of the twenty, these are the questions to put to any security program, ours included, before the next voyage:
- Monitoring that lives aboard. If detection depends on the satellite link, it fails at the moment an intruder cuts the link, which on the VL Prosperity reportedly lasted 30 hours.
- A decoded record of the machinery network. Every device and every write to engine, fuel and ballast controllers, captured passively and kept on the ship.
- Eyes on the satellite terminal. The device that connects the ship to the internet should be the most watched device aboard, not the least.
- The spectrum in the same timeline. GNSS jamming and spoofing, AIS anomalies, drones and rogue emitters, read against what the control network was doing in the same minute.
- Threat intelligence sized for satcom. Signed, rollback-proof bundles that arrive in kilobytes and apply when they land.
- Evidence the regulator and the terminal can read. Monitoring mapped to the CFR sections a CySO is accountable for, per vessel, with the date each ship last reported.
Additional features ready for demo
- Zone and conduit map: the ship's segmentation drawn as a picture of zones and the conduits between them, so a path from the business network to the engine room is visible before it is used.
- Vendor and remote-access inventory: one screen for every vendor and remote-access path into the OT network, including the edges nobody inventories.
- Multi-sensor triangulation: an emitter's position fixed from bearings and timing across several GPS-synced sensors, drawn as rays on the ship's deck plan.
- Live AIS picture: AIS positions searchable within a minute of reception, so the maritime map is current rather than minutes behind.
Put the defense aboard before the next port call
RedEye assesses the paths into a ship's control network, from the satellite terminal to the engine room, and leaves Caver aboard to watch them: sealed on the vessel, decoding the machinery network, listening to the spectrum around the hull, and reporting to shore when the link allows. Owners, managers, charterers and terminals: talk to us.
Talk to us about Caver for your fleetSources: Bloomberg, October 2, 2026; CBS News; CBS News, September 16, 2026; TechCrunch, September 18, 2026; Federal Register, Cybersecurity in the Marine Transportation System. Attribution of the VL Prosperity intrusion is unconfirmed by U.S. authorities as of publication.
