U.S. authorities are investigating whether foreign cyber adversaries were linked to threat activity targeting ships operating in U.S. waters.
The U.S. Coast Guard, working with the FBI and other federal cyber experts, said it boarded a foreign-flagged commercial ship that was sailing toward the U.S on Aug. 21.
“The measures were designed to ensure integrity of the vessel’s operational and information technology systems following indications that the vessel’s networks were compromised by foreign cyber actors,” a Coast Guard spokesperson told Cybersecurity Dive.
FBI officials confirmed that a second, similar boarding was conducted Aug. 24. Both vessels were oil tankers operating in the Gulf of Mexico, en route to Texas, according to multiple reports.
Officials said there are no indications of operational disruption, vessel instability, danger to crew members or impacts on the environment. The ship’s captain, crew and shore-side corporate staff “were critical partners” to ensure any potential threats were mitigated, according to the spokesperson.
The Coast Guard said it is managing communication with port operators, vessel owners and local maritime-industry stakeholders to ensure port operations continue.
Maritime concerns
The incident comes at a time of rising concern about the security of port facilities and vessels entering the U.S.
“The concern specifically for foreign vessels is whether those vessels are adhering to minimum cybersecurity standards that would prevent or mitigate such an attack,” Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies.
The U.S. has increased security requirements for the maritime sector to include mandatory reporting and updated training.
Port facilities and shipping have been the target of prior attacks, including the 2017 attack on Maersk linked to NotPetya and a 2021 intrusion at the Port of Houston.
“Modern tankers run navigation, propulsion, steering and cargo systems on the same onboard network that also carries IT and satellite connectivity, often behind a single firewall,” said Liz Martin, senior director of threat hunting at Dragos, a cybersecurity company that specializes in operational technology risk.