Second Texas-bound oil tanker hit by hackers possibly linked to Iran, Coast Guard confirms an attack
Ship allegedly lost communications for 30 hours with hackers gaining control over engine-room systems.

At-sea transfer, Aug 24, 2026. Image by US Coast Guard Petty Officer 3rd Class Perry Shirzad
- A US-bound tanker carrying nearly 2.3 million barrels of oil suffered a major cyber breach.
- FBI and Coast Guard cyber teams boarded the VL Prosperity to investigate and secure its systems.
- US officials are also investigating a second reported cyberattack on a tanker headed to Texas.
- The Coast Guard reported no crew danger, environmental harm, or operational disruption after the threats were mitigated.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A commercial tanker carrying nearly 2.3 million barrels of oil and headed to Texas is hit by hackers – forcing the ship to call in the FBI and Coast Guard to help mitigate the breach, now linked to Iran. Now, new reports surface Thursday of a second attack on a US-bound tanker.
Furthermore, US officials are “considering whether Iran or an Iran-aligned actor could be responsible,” the Wall Street Journal also reported on Thursday, citing sources familiar with the matter.
The Liberian crude oil tanker, now parked in the Gulf of Mexico, left from Egypt’s Sidi Kerir Oil Terminal on August 1st, with its destination listed as Galveston, Texas, according to the site VesselFinder.
Built in 2015, the VL Prosperity measures 333 meters (~1,093 feet) long and has a deadweight capacity of 319,547 tonnes. It was supposed to arrive in Galveston on August 24th.
But instead, three days before its arrival date, we’re now learning that a “highly specialized team” of FBI and Coast Guard cyber experts descended on the vessel after being called in to investigate a major breach of its systems.
“On August 21, a highly specialized team – comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators – embarked the vessel to conduct a comprehensive cyber security boarding and investigation,”a US Coast Guard spokesperson told Cybernews on Thursday.
The Coast Guard spokesperson said the measures taken as part of the “joint offshore security boarding were designed to ensure the integrity of the vessel’s operational and information technology systems."
This was based on what the Coast Guard said were “indications that the vessel’s network were compromised by foreign cyber actors.”
The video above, released on Wednesday, shows US Coast Guard members assigned to US Coast Guard Cutter Donald Horsley transfer from the cutter to a tanker and conduct operations aboard the tanker in the Gulf of America on August 24, 2026, and is credited to US Coast Guard Petty Officer 3rd Class Perry Shirzad.
Second Texas-bound tanker hit by hackers
The VL Prosperity breach was reported to have taken place while the vessel was traveling through the Strait of Gibraltar, a major shipping chokepoint that has seen heavier traffic since the Iran War has effectively cut off access to the Strait of Hormuz.
The route may be a significant factor in the attack, as the Wall Street Journal's report states that the US is now investigating a second cyberattack on a vessel also bound for Texas and transiting the Strait of Gibraltar.
The Strait of Gibraltar, which connects the Mediterranean Sea with the Atlantic Ocean between Spain and Morocco, sees roughly 300 ships transit the route each day.
The second and slightly smaller tanker – the 227-meter-long Kohaku – was on its way to another Texas port to load liquefied petroleum gas (LPG), the WSJ said.
As of Thursday, the Marshall Islands-flagged LPG tanker appears to be anchored near Malta, VesselFinder shows.
US investigates possible Iran link
The Coast Guard did not name the foreign actor behind the attack, yet Tehran’s state-owned Mehr News Agency was first to identify VL Prosperity as the victim, citing an unnamed crew member on August 20th.
The Mehr report also claimed the attack knocked “all of its communications” offline for 30 hours.
The attackers infiltrated the engine-room systems, reduced the engine’s cooling flow, increased the engine speed, and disabled the ship’s fuel and engine-oil tank,Mehr News Agency reported.
Ironically, although Mehr stated that “No group had yet claimed responsibility for the incident,” the piece also insinuated that the attack was a message from Iran's "Resistance Front" to Washington and the broader Middle East, warning that “international waters do not have immunity” from further action.
Coast Guard actively monitoring
In its statement, the Coast Guard spokesperson said that there are “currently no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts,” referring to the more than three-day incident response operation aboard the "inbound foreign-flagged commercial vessel.”
The US military maritime branch also said it is “actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption,” confirming that the "threats were mitigated."
The Coast Guard further commended the extensive cooperation from the impacted vessel, specifically calling out the tanker’s captain, crew, and shore-side corporate staff.
Maritime partners were further encouraged to “proactively request anonymized cyber assistance,” the Coast Guard said.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.