A federal cyber team boarded a 333-meter supertanker carrying roughly 2.3 million barrels of crude oil in the Atlantic Ocean on August 21, while the vessel was bound for Galveston, Texas. The U.S. Coast Guard confirmed the operation publicly only in mid-September, after journalists started asking questions.
That delay is part of the story. So is the significant gap between what U.S. authorities have confirmed and what Iranian state media claims happened.
What the U.S. Government Has Confirmed
Here is what federal agencies have actually established about the boarding and the suspected breach.
The boarding team included Coast Guard law-enforcement personnel, a vessel inspector, and Coast Guard Cyber Protection Team members. FBI Cyber Action Team operators joined them on board.
Together, they examined both the ship’s operational technology and its IT systems, then worked with the crew and corporate operators to eradicate the suspected threat. U.S. authorities confirmed “indications” that the vessel’s network had been compromised by a foreign actor, and they have not named a culprit.
The Coast Guard’s official position, as reported by CBS News: “Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”
HMM Ocean Service Co., Ltd., the South Korea-based firm that manages the vessel, confirmed to CBS News that VL Prosperity was the tanker in question. The company stated it “has rigorous cyber protocols in place to ensure the safety and security of vessels under our care.”
A second foreign-flagged tanker was boarded on August 24 under similar circumstances. U.S. authorities again reported no operational disruptions.

What Iran Claims, and Why You Should Read It Carefully
Iranian state media published a detailed and aggressive account of the incident, but independent evidence has not confirmed it.
Iran’s semi-official Mehr News Agency reported on August 20 that the attack occurred on August 7, during the ship’s transit near the Strait of Gibraltar, and that communications went dark for 30 hours. Iranian outlets cited a single unnamed crew member as the source for those details.
That source claimed attackers infiltrated engine-room systems, reduced cooling flow, increased engine speed, and disabled fuel and engine-oil monitoring. Tasnim News Agency ran a headline reading: “No American vessel is safe anymore: Will cannons give way to codes?” That is Iranian state-linked media framing, not an established fact.
Here is the critical gap: the VL Prosperity cyber claim originates from a single source, according to maritime intelligence site Seavanta. The ship’s manager, its flag state, UKMTO, and every official maritime reporting body have not confirmed it, and Seavanta does not classify the event as an established cyber casualty.
The distance between Iranian claims of full propulsion and navigation takeover and the U.S. position of “indications of network compromise, no operational impact” is significant. Treat that distance as meaningful, not incidental.
Why Ship OT Is a Different Category of Risk
A network breach on a supertanker carries consequences that a typical office hack simply cannot.
Operational technology on a modern tanker is not a corporate email server. These are the networked systems controlling propulsion, engine cooling, navigation, fuel monitoring, and cargo handling: the ship’s central nervous system, built for reliability long before remote attackers were part of the threat model.
A compromise of propulsion or cooling systems on a 2.3-million-barrel vessel approaching a major port is a categorically different problem from a ransomware attack on an office network. The physical consequences at sea, or near a port handling critical energy supplies, are not theoretical.
What Remains Unresolved
Attribution is open, the investigation is active, and the gap between competing accounts has not closed.
No independent evidence bridges the gap between Iranian claims and U.S. statements. No agency has publicly named a responsible party.
The Coast Guard’s decision to deploy cyber teams mid-voyage confirms one thing clearly. The U.S. government now treats maritime operational technology as critical infrastructure worth defending at sea, not just at the dock. The next question, still unanswered, is who got in, and how far they actually reached.




























