FBI and Coast Guard Board Hacked Oil Tankers Headed for US Coast

FBI and Coast Guard Board Hacked Oil Tankers Headed for US Coast

TL;DR

  • Federal agents, including the FBI and US Coast Guard, boarded multiple compromised oil tankers approaching the US coast after a sophisticated cyberattack disrupted their onboard navigation and propulsion control systems.
  • The hack, attributed to a state-linked threat group, manipulated GPS and thruster controls, forcing one vessel to briefly drift off course in a busy shipping lane before manual overrides were engaged.
  • The FBI’s ongoing investigation reveals a critical vulnerability in commercial maritime systems, warning that similar attacks could be used to cause oil spills, collisions, or blockades at US ports.

The Silent Boarding: A Coordinated Response at Sea

In a scene more reminiscent of a naval thriller than routine port operations, FBI agents and US Coast Guard personnel conducted a high-stakes boarding of three oil tankers as they approached the Eastern Seaboard last week. The vessels, carrying millions of barrels of crude, had become unwitting test subjects for a cyber intrusion that reached into the very heart of their engineering controls.

The operation, confirmed by multiple federal sources, was not triggered by a cargo dispute or a customs violation. Instead, it was a direct response to a cascading series of digital failures that began three days prior, while the ships were still 200 nautical miles offshore. The attack did not merely steal data; it seized control of systems that keep the ships afloat and moving.

How the Hack Hijacked Navigation and Propulsion

The attack targeted the Integrated Bridge System (IBS) and the Propulsion Control System (PCS), two separate networks that are increasingly linked for efficiency. According to preliminary forensic analysis, the intruders used a phishing email sent to a junior officer’s personal tablet, which was connected to the ship’s Wi-Fi for streaming. That single breach provided a pivot point.

Once inside, the attackers deployed a custom malware variant that did not encrypt files—it manipulated sensor data. On the first tanker, the system began displaying false GPS coordinates, showing the vessel 15 miles east of its actual position. More dangerously, the malware sent spurious rudder commands and throttle adjustments. The crew reported the ship suddenly lurching to port while the engine RPMs spiked to unsafe levels, causing violent vibrations.

“The crew saw the autopilot fighting the manual controls,” said a Coast Guard investigator on scene. “The navigation screen showed a clear heading, but the physical helm was turning the opposite way. It was a digital phantom that had control of the iron.” The attackers also disabled the emergency engine stop function for nearly 40 minutes, forcing engineers to manually cut fuel lines in the engine room to regain propulsion authority.

The FBI Investigation: Tracing the Digital Fingerprints

The FBI’s Cyber Division, working with the Coast Guard Investigative Service (CGIS), has recovered the malware samples and is tracing command-and-control servers. While a full attribution report is pending, intelligence briefings indicate the attack pattern matches a known advanced persistent threat (APT) group previously linked to sabotage of energy infrastructure in the Baltic Sea.

Investigators have found that the hackers maintained persistent access for at least 11 days prior to the boarding, quietly mapping the network. They specifically targeted the gyrocompass interface and the thruster control logic controllers. The final phase of the attack was triggered remotely, likely when the ships entered the US Exclusive Economic Zone, suggesting the goal was to cause a visible incident near American shores.

Crucially, the FBI has confirmed that the attack was not financially motivated—no ransom demand was made. The objective appears to be pure disruption and intelligence gathering on how US maritime responders react to a disabled tanker. The agents seized the ships’ voyage data recorders and all IT hardware, but they also found that the attackers had wiped the primary backup logs, indicating a high level of operational security.

Why This Threat Is Different from Past Maritime Hacks

Previous maritime cyber incidents, such as the 2017 NotPetya attack on Maersk, primarily disrupted logistics and billing systems. This new attack crossed a dangerous threshold: it touched safety-critical operational technology (OT). The distinction matters because OT systems are designed for reliability, not security. They often run on legacy protocols that lack authentication, meaning a valid command from a compromised network is treated as legitimate.

The Coast Guard has issued a rare safety alert to all commercial vessels, warning that this specific malware can spoof Automatic Identification System (AIS) signals. This means a hacked tanker could appear on other ships’ radar as a different vessel or a stationary buoy, creating a massive collision risk in congested lanes like the approaches to New York and Houston.

The Growing Threat to US Infrastructure

This incident underscores a broader national security concern. The US relies on waterborne commerce for over 95% of its overseas trade, and oil tankers are the lifeblood of energy supply. A successful attack on a single tanker in a narrow channel could block a port for days, causing billions in economic damage and potential environmental catastrophe from a grounding.

Federal agencies are now urging shipping companies to treat their onboard networks as critical infrastructure, not just office IT. The investigation has revealed that most of the tankers’ crews had no training in identifying a cyber-induced mechanical failure, initially blaming the issues on bad weather or mechanical faults. This gap in human readiness is as significant as the technical vulnerability.

What Happens Next

The three tankers are currently anchored in a designated safety zone off the coast, guarded by Coast Guard cutters. They are undergoing a full forensic audit and will only be allowed to dock after their control systems are wiped and reinstalled from clean, verified sources. The FBI has also served subpoenas to the satellite communication providers used by the vessels to trace the initial intrusion vector.

As the investigation continues, one thing is clear: the era of purely digital espionage at sea is over. The next phase of maritime conflict involves hackers who are willing to risk lives and the environment to make a point. The US coast is now officially a contested digital frontier, and this boarding was the first shot across the bow.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
FBI and Coast Guard Board Hacked Oil Tankers Headed for US Coast FBI and Coast Guard Board Hacked Oil Tankers Headed for US Coast Reviewed by Randeotten on 9/18/2026 11:56:00 PM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.