US Tracking Cyber Threats Against Nearly 20 Ships Worldwide — What Investigators Found on Two Vessels Raises New Alarms

United States

US Tracking Cyber Threats Against Nearly 20 Ships Worldwide — What Investigators Found on Two Vessels Raises New Alarms

WASHINGTON — US government agencies are tracking potential cyber threats involving nearly 20 commercial shipping vessels around the world, raising fresh concerns about the vulnerability of increasingly digitised maritime operations and global supply chains.

US officials familiar with the matter told Bloomberg that the US Coast Guard has asked for advance notice if any of the vessels under scrutiny plan to enter a US port. The specific destinations and cargo manifests of the ships were not immediately disclosed.

The development follows a series of suspected cyber incidents involving commercial vessels in recent weeks. According to US officials, several ships were targeted in potential attacks in late August, although there was no indication that hackers had taken control of the vessels themselves.

Two vessels boarded in the Gulf of Mexico

The US Coast Guard confirmed that it boarded two foreign-flagged commercial vessels arriving in the Gulf of Mexico after receiving indications that their operational and information-technology networks had been compromised.

The first vessel was boarded on August 21, followed by a second on August 24.

The Coast Guard said there were no reported operational disruptions, vessel instability, danger to crews or environmental impacts at the time of its statement. Officials said they were working with vessel owners, port operators and other maritime stakeholders to address the potential threats.

The investigations involve the Coast Guard, the FBI and components of the Department of Homeland Security, according to US officials cited by Bloomberg.

Investigators examine possible Iran connection

The incidents have also triggered scrutiny over whether Iran or an Iran-linked actor could be connected to attacks against at least two energy tankers bound for US ports.

The Wall Street Journal reported that US authorities were investigating a possible Iranian connection to cyberattacks affecting two tankers travelling toward Texas. The vessels were reportedly targeted while transiting the Strait of Gibraltar in early August.

However, the attribution remains under investigation. There has been no definitive public finding establishing that Iran was responsible.

One of the vessels, the VL Prosperity, reportedly experienced a prolonged communications disruption while travelling through the Strait of Gibraltar. The Financial Times reported that the US Coast Guard boarded the vessel on August 21 to assess the integrity of its operational and information-technology systems.

Why ships are becoming attractive cyber targets

The maritime industry has undergone rapid digitalisation, with modern vessels increasingly dependent on connected systems for navigation, communications, engine management and other onboard functions.

That connectivity can create additional pathways for attackers.

The Financial Times, citing maritime cybersecurity company Cydome, reported that satellite-connected “edge devices” accounted for 22 per cent of maritime cyberattacks recorded by the company in 2025, compared with 3 per cent in 2024. Cydome said the absolute number of attacks was in the hundreds.

Cybersecurity researchers have warned that the consequences can extend beyond stolen information. If attackers penetrate systems connected to operational technology, they could potentially interfere with functions associated with navigation, propulsion or other critical equipment.

At the same time, experts caution that not every cyber incident results in control of a vessel. Many attacks are aimed at ransomware, data theft, credential compromise or disruption rather than physically commandeering a ship.

Old technology adds another layer of risk

Some vessels continue to operate equipment designed decades ago, when cybersecurity was not a major consideration.

Maria Bartnes, cybersecurity research programme director at DNV, told Bloomberg that older operational systems can be particularly difficult to update and were developed at a time when the threat of cyberattacks was much lower.

CyberOwl, a maritime cybersecurity company, has also reported a rise in incidents involving ships during the first half of 2026.

According to information cited by Bloomberg, more than half of the attempted intrusions detected by CyberOwl on vessels it monitors involved malware being introduced through storage devices. Other incidents involved internet downloads or phishing.

The US is strengthening maritime cyber defences

The heightened attention comes as Washington expands its focus on maritime cybersecurity.

On August 31, the US Coast Guard announced the creation of its Office of Maritime Cybersecurity Policy, saying increased use of information and operational technology was bringing greater cybersecurity risks to the maritime transportation system.

The agency said the new office would support the development of policies, standards and guidance aimed at strengthening the cyber resilience of the maritime sector.

The issue extends beyond individual ships. Ports, terminals, logistics companies and shipping networks are all increasingly dependent on interconnected digital infrastructure.

The Port of Los Angeles, for example, reported blocking more than 120 million cyberattack attempts in August, illustrating the scale of persistent digital threats facing major trade gateways.

A threat to shipping — but no evidence of a global takeover

Despite the growing number of warnings, officials have not said that the nearly 20 vessels being monitored are all victims of a coordinated cyberattack.

The US investigation is continuing, and authorities have not publicly identified every vessel, the precise nature of the suspected threats or those responsible.

The Coast Guard has also said that, in the two vessels it boarded in August, there were no reported operational disruptions, instability, physical danger to crews or environmental consequences at that point.

What the incidents demonstrate, however, is how cybersecurity has become increasingly intertwined with maritime security.

For an industry responsible for moving a substantial share of global trade, even temporary disruption to navigation, communications or cargo operations could have consequences well beyond a single vessel.

And as ships become more connected to satellites, ports and shore-based systems, investigators and cybersecurity experts are watching closely for signs that today’s attempted intrusions could evolve into a much broader threat to the global shipping network.

More in Asia

See all in Asia