U.S. authorities are investigating suspected cyber activity targeting commercial vessels operating in or approaching U.S. waters, including the possibility that foreign cyber adversaries were involved.
The U.S. Coast Guard, working alongside the FBI and other federal cybersecurity specialists, boarded a foreign-flagged commercial vessel sailing toward the United States on August 21. According to a Coast Guard spokesperson, the operation was carried out after indications that the vessel’s networks may have been compromised by foreign cyber actors.
“The measures were designed to ensure integrity of the vessel’s operational and information technology systems following indications that the vessel’s networks were compromised by foreign cyber actors,” the spokesperson told Cybersecurity Dive.
FBI officials subsequently confirmed that a second, similar boarding took place on August 24. Both vessels were oil tankers operating in the Gulf of Mexico and heading toward Texas, according to multiple reports.
Despite the suspected cyber incidents, authorities said there were no indications of operational disruption, vessel instability, danger to crew members or environmental impacts.
The Coast Guard also highlighted the role of the vessels’ crews and shore-based corporate teams in the response. The ship’s captain, crew and corporate personnel on shore were described as “critical partners” in identifying and mitigating any potential threats.
At the same time, the Coast Guard is coordinating communications with port operators, vessel owners and other local maritime-industry stakeholders to help ensure that port activities continue without interruption.
Maritime cybersecurity under closer scrutiny
The investigation comes as cybersecurity concerns continue to grow around ships and port facilities entering the United States.
For foreign-flagged vessels in particular, one of the questions is whether their cybersecurity practices meet the minimum standards needed to prevent or limit the consequences of an attack, according to Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies.
U.S. maritime cybersecurity requirements have also been strengthened, with measures including mandatory reporting obligations and updated training requirements.
The shipping industry has already experienced major cyber incidents. Among the best-known examples is the 2017 attack on Maersk linked to NotPetya, while the Port of Houston was hit by a cyber intrusion in 2021.
The architecture of modern vessels adds another layer of exposure. Liz Martin, senior director of threat hunting at cybersecurity company Dragos, noted that contemporary tankers can operate navigation, propulsion, steering and cargo systems on the same onboard network that also handles IT and satellite connectivity, with these systems often protected by a single firewall.
The latest U.S. investigation therefore places renewed attention on the cybersecurity of commercial vessels as they approach ports and operate within U.S. maritime waters.





















