FBI and Coast Guard Investigated Possible Network Compromises on Two Tankers

The U.S. Coast Guard and FBI investigated possible compromises of IT and OT networks on two foreign-flagged oil tankers bound for the United States.

Possible tanker network compromises were investigated by the FBI and U.S. Coast Guard after indications that the networks of two foreign-flagged commercial oil vessels bound for the United States had been compromised. A joint team of U.S. agencies examined both information systems and operational technology aboard the vessels.

The interventions took place on August 21 and 24, 2026, in the Gulf of Mexico, while authorities publicly communicated them on September 15 and 16. According to a joint statement by the U.S. Coast Guard and FBI, no operational outages, instability affecting the vessels, threats to crews, or environmental impact had been reported at the time of publication.

Possible tanker network compromises in both IT and OT environments

The investigation involved more than corporate and communications networks. The team also examined the OT environment, meaning the technologies used to operate the vessels. Authorities did not specify which systems they checked or the nature of the possible compromise.

U.S. agencies also communicated with port operators, shipowners, and local maritime partners. The stated aim was to maintain safe port operations while the incidents were being investigated.

According to available information, the vessels were two foreign-flagged commercial oil ships bound for the United States. Public statements did not identify the ships, their operators, or specific ports.

Scope of intrusions remains undisclosed

Neither the FBI nor the Coast Guard publicly attributed the incidents to a specific perpetrator or state. It has also not been confirmed what the scope of the possible intrusion was, which systems were affected, or whether the two cases were related.

There is also no public confirmation that anyone took control of the propulsion, navigation, or cargo systems of either tanker. U.S. authorities have not confirmed such claims.

The case is a confirmed investigation into possible cyber compromises in maritime energy transportation, not confirmation of operational disruption or physical damage. The distinction between an indication of compromise and a documented operational impact is significant given the available information.

Why the investigation matters

Tankers use information networks alongside systems intended to operate the vessel. The deployment of a joint FBI and Coast Guard team aboard the ships indicates that authorities are treating the case as a risk to critical maritime infrastructure.

At this stage, however, it is not possible to assess the intrusion technique, the severity of the compromise, or whether specific remedial measures were needed. Authorities have not disclosed technical indicators of compromise, the method of entry into the networks, or recommended mitigations for ship operators.

What may happen next

Further information may come from a forensic investigation. Of particular importance will be any possible release of technical indicators, the scope of the impact on the IT and OT environments, or attribution of the incidents to a specific actor. It will also be important to monitor whether U.S. authorities announce similar cases or new measures for ports and ship operators.

Sources

  • Associated Press – Confirms the dates of the two interventions, the involvement of a multi-agency cyber team, and the absence of known operational or environmental consequences.
  • CyberScoop – Quotes a joint Coast Guard and FBI statement about compromised networks and the examination of the vessels’ IT and OT systems.
  • CBS News – Reports Coast Guard confirmation that a specialized team intervened aboard a foreign-flagged vessel after indications that its network had been compromised by a foreign actor.
  • The Record – Original report on U.S. authorities’ intervention aboard a tanker and the purpose of checking the integrity of its operational and information systems.

Verified and updated: 09/17/2026 06:25

Sharing