“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts,” the Coast Guard and FBI said in a joint statement about two U.S.-bound commercial ships boarded last month after indications their networks had been compromised.
Coast Guard and FBI board two tankers in the Gulf of Mexico
On Aug. 21 and Aug. 24, the Coast Guard and the FBI conducted what the agencies called “joint offshore security boardings” of two foreign commercial vessels in the Gulf of Mexico. The boardings were carried out “to conduct a comprehensive cyber security boarding and investigation,” according to the joint statement. The vessels were reportedly tankers carrying oil and natural gas.
The Aug. 21 boarding party included Coast Guard law enforcement personnel, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators. A similar composition made up the Aug. 24 boarding party. The agencies said the captain, crew, and shore-side corporate staff “were critical partners in helping to ensure the threats were mitigated.”
The suspected cyber intrusions and immediate impacts
Both boardings followed indications that the networks of the two vessels had been compromised. Authorities described the actions as designed “to ensure integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised.”
Officials reported no operational disruptions, no instability, no physical danger to crews and no environmental impact stemming from the incidents. One of the vessels reportedly lost communication for over 30 hours after being hacked in the Strait of Gibraltar, a detail that helped prompt the subsequent offshore security boarding once the ship neared U.S. waters.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDark fleets, digital masking and elevated cyber risks
Coast Guard cyber teams have for months been focused on so-called “dark fleets,” the joint statement and reporting referenced in the agencies’ public material noted. These dark fleets are described as vessels that carry sanctioned oil from Iran and Russia and that rely on digital masking to hide their operations — a practice the agencies say carries enhanced cyber risks. The Wall Street Journal reported on that activity in June.
Investigators are also probing motive and origin. Authorities were said to be investigating whether Iran, or “perhaps another group seeking to exploit the conflict between Iran and the United States,” was behind the suspected attacks, according to the reporting contained in the statement.
Authorities’ legal and operational tools: the 2024 executive order
The Coast Guard’s role in responding to maritime cybersecurity incidents expanded after an executive order signed in 2024 by then-President Joe Biden. The order gave the Coast Guard additional authorities to respond to cybersecurity incidents, citing the risks that a maritime cyber incident could cause “cascading” harm to the global supply chain. The boardings in August were conducted under those broader operational authorities and coordination arrangements.
What this means for port operators, vessel crews, and investigators
- Port operators: The Coast Guard said it is “actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption,” signaling close coordination to prevent disruption despite ongoing investigations.
- Vessel crews and corporate staff: The joint statement emphasized that the captain, crew, and shore-side corporate staff were “critical partners” in mitigating threats, underscoring the operational role onboard and in corporate control centers during cyber incidents.
- Investigators and law enforcement: The use of Coast Guard Cyber Protection Teams alongside FBI Cyber Action Team operators illustrates the combined maritime and federal cyber-investigative approach authorities deployed to examine both operational technology and information technology systems on board.
Two offshore boardings, two investigations, and at least one ship with a multi-day communications outage: the episodes in August underscored the maritime domain’s exposure to cyber risk and the federal government’s willingness to use combined law enforcement and cyber teams at sea. Authorities continue to investigate attribution and the precise technical scope of the compromises; the public record so far stops short of naming a perpetrator. The full results of those inquiries — and any operational or policy changes that follow — remain to be announced by the agencies involved.




