
US Investigates Alleged Cyberattacks on Tankers in Strait of Gibraltar
The United States is investigating alleged cyberattacks on tankers that were reportedly carried out while two US-bound vessels were transiting the Strait of Gibraltar in August, raising new concerns about maritime cybersecurity, vessel systems and shipping security.
The two tankers were allegedly hacked by unknown actors during their passage through the strategically important waterway. The VL Prosperity was carrying crude oil, while the second vessel, identified in US reports as Kohaku, was transporting liquefied petroleum gas (LPG).
A specialist team led by the US Coast Guard, including agents from the Federal Bureau of Investigation (FBI), reportedly boarded the vessels after they arrived in the Gulf of Mexico to examine possible malicious cyber activity.
Reports of the incidents first emerged in Iranian state media in late August. The alleged attacks occurred amid heightened tensions affecting international shipping, including disruptions around the Strait of Hormuz, a key route for global oil supplies.
The developments have drawn attention to the vulnerability of commercial vessels operating on strategically important maritime routes. A cyber incident affecting navigation, propulsion or other operational systems could create both safety and commercial risks for shipowners and operators.

Iranian reports about the VL Prosperity cited an unnamed crew member who claimed that hackers breached systems connected to the engine room. The alleged intrusion reduced engine cooling flow, increased engine speed and interfered with fuel systems.
The US Coast Guard has not attributed the alleged attacks to Iran or any other actor and has not publicly identified the vessels involved in its investigation.
Rear Admiral Amy Grable, commander of the US Coast Guard Cyber Command, told CBS News that investigators were searching for malware and examining the ships’ information technology systems.
According to Grable, investigators found malicious cyber activity and were assessing whether onboard IT systems were connected to operational systems controlling propulsion, navigation and other safety-critical functions.
US authorities are also investigating whether the two incidents were connected and whether a foreign adversary was responsible.
The manager of the VL Prosperity separately confirmed that US authorities conducted a cybersecurity screening aboard the vessel. The ship was subsequently cleared for normal operations.
Strait of Gibraltar is a Major Maritime Security Route
The Strait of Gibraltar is one of the world’s busiest waterways, with around 300 vessels passing through each day. Its importance to international trade means a serious cyber incident could potentially affect commercial shipping and maritime operations in the region.
The UK Ministry of Defence was asked whether it was aware of the allegations and what measures were being taken. The MoD, which does not normally comment on operational matters, had not immediately responded.
Authorities in Gibraltar have previously identified malicious cyber activity, sabotage, disinformation and other hybrid threats as risks to UK interests, critical infrastructure and strategic locations.
Earlier this month, the Gibraltar Contingency Council said these threats were included in its continuous assessments. It did not provide details of any specific maritime incident but said relevant agencies would continue monitoring developments and coordinating with UK partners.
Cybersecurity Becomes Part of Maritime Risk Management
The alleged tanker incidents highlight the growing importance of cybersecurity in the shipping industry. Modern vessels rely on interconnected digital systems for navigation, communications, propulsion, cargo operations and other essential functions.
The International Maritime Organization (IMO) has warned that onboard information technology (IT) and operational technology (OT) systems can be targeted by cyber threats. Its maritime cyber risk management approach focuses on protecting ships, ports, marine facilities and other parts of the maritime transportation system.
The key concern is the connection between conventional IT networks and operational systems. If attackers gain access to systems linked to propulsion or navigation, a cyber incident could move beyond data theft or communications disruption and potentially affect vessel safety.
Read:Cyberattacks Surge in Maritime Sector, Persistent Vessel Tracking Becomes Critical
This issue is becoming increasingly important as shipping becomes more digitalized and autonomous vessel technologies develop.
For shipowners, operators and maritime authorities, the reported incidents underscore the need to integrate maritime cybersecurity into wider maritime security and risk management strategies.
