Breaking NewsUpdated as information becomes available
News·Breach Analysis·17 September 2026·Breaking

FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
An oil tanker at night overlaid with a cyan network grid, a magenta intrusion thread running toward the bridge, with a coast guard vessel shining a searchlight in the distance
An oil tanker at night overlaid with a cyan network grid, a magenta intrusion thread running toward the bridge, with a coast guard vessel shining a searchlight in the distance

Why it matters

What this means for organisations holding critical data

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

The FBI and the US Coast Guard are investigating suspected cyberattacks on commercial ships entering US waters, after two foreign-flagged oil tankers were boarded in the Gulf of Mexico in August, according to Cybersecurity Dive.

The Coast Guard said it boarded the first vessel on 21 August while it sailed toward the United States, with a second, similar boarding confirmed by the FBI on 24 August. Both vessels were oil tankers en route to Texas.

A Coast Guard spokesperson said the measures were designed to ensure the integrity of the vessels'' operational and information technology systems following indications that the ships'' networks were compromised by foreign cyber actors. Officials said there were no indications of operational disruption, vessel instability, danger to crew or environmental impact, and credited the ships'' captains, crews and shore-side corporate staff as critical partners in mitigating the threats.

The Coast Guard is managing communication with port operators, vessel owners and maritime industry stakeholders to keep port operations running while the investigation continues.

A ship is an operational technology network with a hull around it

A modern tanker is not simply a vessel with some computers aboard. Navigation, propulsion control, cargo management, ballast and safety systems all run on networked operational technology, sitting alongside the crew''s information technology, satellite communications and shore connections. When officials board to verify the integrity of both OT and IT, they are acknowledging the thing the maritime industry has spent a decade resisting: the network is the ship.

That is why the boarding detail matters. This was not a forensics image taken remotely or a log review conducted from shore. Federal agents physically went aboard to establish the state of systems they could not otherwise trust. When you cannot be sure what a connected system is doing, physical presence becomes the audit tool of last resort.

The pattern is familiar

The maritime sector has been here before. The 2017 NotPetya attack on Maersk remains the defining example of how quickly a compromised network becomes a compromised operation, halting terminals and forcing a rebuild of tens of thousands of machines. The 2021 intrusion at the Port of Houston showed port infrastructure itself in scope. The US has since tightened Maritime Transportation Security Act requirements, adding mandatory cyber incident reporting and updated training.

These boardings suggest the threat has moved from ports to the vessels themselves, and that authorities now treat a suspect network on an inbound tanker the way they would treat suspect cargo: something to be inspected before it reaches the dock.

Annie Fixler of the Foundation for Defense of Democracies put the policy question plainly: whether foreign vessels are adhering to minimum cybersecurity standards that would prevent or mitigate such an attack. The boardings are what happens when the answer cannot be taken on trust.

What organisations should take from this

First, every operational environment that touches the internet should be assumed reachable by a motivated adversary. If a tanker in the Gulf of Mexico is a target, so is a plant floor, a clinic or a depot.

Second, separate what must be connected from what must merely be kept. Voyage records, maintenance histories, manifests and compliance archives do not need to live on the same reachable networks as live systems. Data that is not online cannot be the beachhead, the leverage or the ransom. Offline Secure Storage exists for exactly this class of data: the records an operation must retain but does not need connected.

Third, plan for verification, not just prevention. The Coast Guard could board because there was a physical asset to board. Most organisations do not have that option, which makes continuous logging, integrity checking and tested recovery the only stand-ins for certainty.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker