---
title: "FBI and Coast Guard board oil tankers after sus… | Firevault"
description: "US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026#webpage",
      "url": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026",
      "name": "FBI and Coast Guard board oil tankers after sus…",
      "description": "US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/us-coast-guard-tanker-cyberattacks-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters",
          "item": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters",
      "description": "US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.",
      "url": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/us-coast-guard-tanker-cyberattacks-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/us-coast-guard-tanker-cyberattacks-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/us-coast-guard-tanker-cyberattacks-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/us-coast-guard-tanker-cyberattacks-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-17T14:00:00+00:00",
      "dateModified": "2026-09-18T05:36:25.728276+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 635,
      "keywords": "Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The FBI and the US Coast Guard are investigating suspected cyberattacks on commercial ships entering US waters, after two foreign-flagged oil tankers were boarded in the Gulf of Mexico in August, according to Cybersecurity Dive. The Coast Guard said it boarded the first vessel on 21 August while it sailed toward the United States, with a second, similar boarding confirmed by the FBI on 24 August. ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened in the Gulf of Mexico?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The US Coast Guard boarded a foreign-flagged oil tanker on 21 August 2026 after indications its networks were compromised by foreign cyber actors. The FBI confirmed a second, similar boarding on 24 August. Both vessels were oil tankers en route to Texas."
          }
        },
        {
          "@type": "Question",
          "name": "Were the ships damaged or crews harmed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Officials said there were no indications of operational disruption, vessel instability, danger to crew members or environmental impacts. The captains, crews and shore-side corporate staff were described as critical partners in mitigating the threats."
          }
        },
        {
          "@type": "Question",
          "name": "Why did authorities physically board the vessels?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The boardings were designed to ensure the integrity of the vessels'' operational and information technology systems. When a connected system cannot be trusted remotely, physical inspection becomes the only reliable way to establish its state."
          }
        },
        {
          "@type": "Question",
          "name": "Has the maritime sector been targeted before?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. The 2017 NotPetya attack on Maersk crippled terminals worldwide, and the Port of Houston suffered an intrusion in 2021. The US has since strengthened Maritime Transportation Security Act requirements, including mandatory cyber incident reporting and updated training."
          }
        },
        {
          "@type": "Question",
          "name": "What is the risk to operational technology on ships?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Navigation, propulsion control, cargo management and safety systems run on networked operational technology alongside crew IT and satellite links. A compromise of these networks can threaten the vessel itself, which is why authorities treat a suspect ship network like suspect cargo."
          }
        },
        {
          "@type": "Question",
          "name": "What should organisations learn from this incident?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Assume any internet-connected operational environment is reachable by motivated adversaries, separate records that must be kept from systems that must be live by moving archives into disconnected storage such as Offline Secure Storage, and invest in continuous logging, integrity checking and tested recovery so the state of a system can be verified without a physical boarding."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

A ship is an operational technol…The pattern is familiarWhat organisations should take f…SourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 17 September 2026 · Breaking 

# FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026&text=FBI%20and%20Coast%20Guard%20board%20oil%20tankers%20after%20suspected%20foreign%20cyberattacks%20on%20ships%20entering%20US%20waters%0A%0AUS%20authorities%20boarded%20two%20foreign-flagged%20oil%20tankers%20in%20the%20Gulf%20of%20Mexico%20after%20indications%20their%20networks%20were%20compromised%20by%20foreign%20cyber%20actors.%20Mark%20Fermor%20on%20why%20a%20ship%20is%20a%20floating%20lesson%20in%20what%20happens%20when%20operational%20technology%20is%20reachable.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[](mailto:?subject=FBI%20and%20Coast%20Guard%20board%20oil%20tankers%20after%20suspected%20foreign%20cyberattacks%20on%20ships%20entering%20US%20waters&body=US%20authorities%20boarded%20two%20foreign-flagged%20oil%20tankers%20in%20the%20Gulf%20of%20Mexico%20after%20indications%20their%20networks%20were%20compromised%20by%20foreign%20cyber%20actors.%20Mark%20Fermor%20on%20why%20a%20ship%20is%20a%20floating%20lesson%20in%20what%20happens%20when%20operational%20technology%20is%20reachable.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)

![An oil tanker at night overlaid with a cyan network grid, a magenta intrusion thread running toward the bridge, with a coast guard vessel shining a searchlight in the distance](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

An oil tanker at night overlaid with a cyan network grid, a magenta intrusion thread running toward the bridge, with a coast guard vessel shining a searchlight in the distance

Why it matters

## What this means for organisations holding critical data

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

In this analysis

1.  01 [A ship is an operational technol…](#section-0)
2.  02 [The pattern is familiar](#section-1)
3.  03 [What organisations should take f…](#section-2)

**On this page**[A ship is an operational technol…](#section-0)[The pattern is familiar](#section-1)[What organisations should take f…](#section-2)

The FBI and the US Coast Guard are investigating suspected cyberattacks on commercial ships entering US waters, after two foreign-flagged oil tankers were boarded in the Gulf of Mexico in August, according to Cybersecurity Dive.

The Coast Guard said it boarded the first vessel on 21 August while it sailed toward the United States, with a second, similar boarding confirmed by the FBI on 24 August. Both vessels were oil tankers en route to Texas.

A Coast Guard spokesperson said the measures were designed to ensure the integrity of the vessels'' operational and information technology systems following indications that the ships'' networks were compromised by foreign cyber actors. Officials said there were no indications of operational disruption, vessel instability, danger to crew or environmental impact, and credited the ships'' captains, crews and shore-side corporate staff as critical partners in mitigating the threats.

The Coast Guard is managing communication with port operators, vessel owners and maritime industry stakeholders to keep port operations running while the investigation continues.

## A ship is an operational technology network with a hull around it

A modern tanker is not simply a vessel with some computers aboard. Navigation, propulsion control, cargo management, ballast and safety systems all run on networked operational technology, sitting alongside the crew''s information technology, satellite communications and shore connections. When officials board to verify the integrity of both OT and IT, they are acknowledging the thing the maritime industry has spent a decade resisting: the network is the ship.

That is why the boarding detail matters. This was not a forensics image taken remotely or a log review conducted from shore. Federal agents physically went aboard to establish the state of systems they could not otherwise trust. When you cannot be sure what a connected system is doing, physical presence becomes the audit tool of last resort.

## The pattern is familiar

The maritime sector has been here before. The 2017 NotPetya attack on Maersk remains the defining example of how quickly a compromised network becomes a compromised operation, halting terminals and forcing a rebuild of tens of thousands of machines. The 2021 intrusion at the Port of Houston showed port infrastructure itself in scope. The US has since tightened Maritime Transportation Security Act requirements, adding mandatory cyber incident reporting and updated training.

These boardings suggest the threat has moved from ports to the vessels themselves, and that authorities now treat a suspect network on an inbound tanker the way they would treat suspect cargo: something to be inspected before it reaches the dock.

Annie Fixler of the Foundation for Defense of Democracies put the policy question plainly: whether foreign vessels are adhering to minimum cybersecurity standards that would prevent or mitigate such an attack. The boardings are what happens when the answer cannot be taken on trust.

## What organisations should take from this

First, every operational environment that touches the internet should be assumed reachable by a motivated adversary. If a tanker in the Gulf of Mexico is a target, so is a plant floor, a clinic or a depot.

Second, separate what must be connected from what must merely be kept. Voyage records, maintenance histories, manifests and compliance archives do not need to live on the same reachable networks as live systems. Data that is not online cannot be the beachhead, the leverage or the ransom. [Offline Secure Storage](/offline-secure-storage) exists for exactly this class of data: the records an operation must retain but does not need connected.

Third, plan for verification, not just prevention. The Coast Guard could board because there was a physical asset to board. Most organisations do not have that option, which makes continuous logging, integrity checking and tested recovery the only stand-ins for certainty.

## Sources

-   [Cybersecurity Dive: FBI, Coast Guard probe suspected cyberattacks on ships entering US waters](https://www.cybersecuritydive.com/news/fbi-coast-guard-probe-cyberattacks-ships-us-waters/830668/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![CenterPoint Energy confirms hackers stole customer data through an exposed API](/news/centerpoint-energy-cyberattack-2026.jpg)

Breach Analysis 

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min 







](/news/centerpoint-energy-confirms-cyberattack-data-theft-2026)[

![Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details](/news/southampton-council-data-breaches-2026.jpg)

Breach Analysis 

### Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

16 Sept 2026 5 min 







](/news/southampton-council-seven-serious-data-breaches-2026)[

![Southport court files breach: the access was authorised, the purpose was not](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Breach Analysis 

### Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

16 Sept 2026 5 min 







](/news/southport-court-files-insider-access-breach-2026)[

![Military flight plan reportedly triggered the NATS outage, unless you ask the MoD](/news/nats-outage-military-flight-plan-2026.jpg)

Breach Analysis 

### Military flight plan reportedly triggered the NATS outage, unless you ask the MoD

Flight data filed for a UK military aircraft reportedly set off the 8 September NATS failure, according to the Financial Times. The Ministry of Defence says there was no error on its part. Mark Fermor on what a single filing emptying the national schedule says about resilience.

12 Sept 2026 5 min 







](/news/nats-outage-military-flight-plan-resilience-2026)[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)