Coast Guard personnel and FBI agents boarded two Texas-bound energy tankers last month after cyberattacks struck the vessels while they were traveling toward the United States, according to U.S. officials. One of the vessels was the VL Prosperity, a 1,093-foot Liberian-flagged crude oil tanker headed to Galveston, Texas. Iranian state media identified the ship shortly after the incident and claimed hackers had gained access to its propulsion, navigation and cargo systems, knocking out communications for 30 hours.
The Coast Guard has not publicly pinned the attacks on Iran. Amy Grable, commander of U.S. Coast Guard Cyber Command, told CBS News in a network exclusive interview that investigators did find evidence of a malicious cyber actor.
"They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity," Grable said. The U.S. is investigating whether the two cyberattacks are connected and whether Iran or another foreign adversary was behind the attacks. The VL Prosperity is what's known as a supertanker — more than three football fields long and capable of carrying roughly 2.3 million barrels of oil.
Public vessel data shows the ship departed Egypt's Sidi Kerir oil terminal on Aug. 1 headed for Galveston. U.S. officials say it slowed near the Strait of Gibraltar around the time of the cyberattack before continuing across the Atlantic and toward the U.S. Iran's Mehr News Agency reported on Aug. 20 that the VL Prosperity had been attacked on Aug. 7 while transiting through the Strait of Gibraltar.
Citing an unnamed crew member, Mehr alleged hackers breached the engine room, reducing engine cooling flow, increasing engine speed and interfering with fuel systems. Rob Lee, CEO of Dragos, an industrial cybersecurity firm specializing in operational technology, said the Iranian report's details were technically plausible, but warned that authorities have not yet revealed who was behind the incident. "The details that they published, from what we understand of these types of vehicles and ships and similar, is spot on," Lee said.
"Everything they're saying is very realistic." The next day, Aug. 21, Coast Guard cyber personnel, law enforcement officers, a vessel inspector and FBI Cyber Action Team operators boarded the ship for four days. Grable said Coast Guard teams had been alerted by interagency partners and went offshore with the FBI to climb aboard — one of roughly 40 to 50 missions the Coast Guard's Cyber Protection Team has undergone in the past year. She said investigators were hunting for malware and combing through information technology systems to root out malicious activity.
Extract — continue reading at the source.