The U.S. Coast Guard and the Federal Bureau of Investigation are investigating cyberattacks on at least two foreign-flagged oil tankers headed for Texas. One such investigation involved the boarding of a vessel on August 21, following intelligence suggesting its network had been compromised by overseas cyber actors. Another boarding by U.S. military forces and FBI agents was reported on September 15 for a similar investigation.
These incidents highlight broader concerns about "dark fleet" tankers, which are used to ferry sanctioned oil and often operate with a mishmash of insecure digital tools. U.S. Coast Guard cyber teams, through various boardings, have discovered that these vessels frequently use high-bandwidth communication systems, remote desktop applications like AnyDesk and TeamViewer, and even pirated software laden with malware. These vulnerabilities could be exploited to cause explosions, oil spills, or allow remote deletion of data, as was attempted in at least one instance after a U.S. boarding.
Rear Adm. Jason Tama, head of the Coast Guard's Cyber Command, emphasized that while the physical risks of these older, poorly maintained ships were known, the extent of cyber threats was not. The cyber teams also uncovered digital subterfuge, such as vessels using multiple Automatic Identification System (AIS) devices, toggle switches to change vessel names electronically, and custom-made Ethernet cables to push out fake location data, demonstrating intentional illicit activity. The Coast Guard hopes that releasing these findings will encourage other countries to increase efforts to interdict these risky vessels.