Federal agents boarded a 333 meter tanker identified by CBS as the VL Prosperity after hackers reportedly seized its navigation, propulsion, and cargo systems. Iran is a possible, unconfirmed link.
On August 24, FBI agents and U.S. Coast Guard personnel climbed aboard a 333-meter oil tanker in the Gulf of Mexico. The vessel, identified by CBS News as the VL Prosperity, can carry more than 2 million barrels of crude. The agencies were not responding to a hijacking. They were responding to a cyberattack that, by the joint statement from the FBI and Coast Guard, had given outsiders control of the ship's navigation, propulsion, and cargo systems (TechCrunch).
The boarding was the public end of a compromise that began more than two weeks earlier. CBS, citing Iranian media, reported that the attackers hit the VL Prosperity on August 7 while it was sailing from Egypt to the United States, interfered with the ship's speed and fuel systems, and cut its communications for more than a day (CBS News). The ship was still in the Gulf of Mexico in mid-September, according to vessel-tracking data.
The ship kept moving through the compromise, which is the part the joint statement's "no operational disruptions" language does not explain. The public record does not show whether the attackers acted on the control of navigation, propulsion, and cargo systems the agencies describe, or whether the crew and onboard systems held the ship to its plotted route.
The FBI and Coast Guard boarded a second US-bound tanker in the same window, between August 21 and August 24, after indications that its networks had also been compromised. The agencies' joint statement described the boardings as precautionary: a physical check of operational and information technology systems to confirm integrity, with the captain, crew, and on-shore staff of the vessel's owner cooperating throughout. The same statement explicitly noted no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts (AP News, SecurityWeek).
The agencies' calm language sits next to a different picture. A maritime cyber compromise, until recently, lived mostly in the abstract: a fleet operator's IT network breached, a satellite communications link probed, a port's logistics platform disrupted. The agencies' description is concrete. Outsiders reached the systems that move the ship and handle its cargo. A Coast Guard visit is the response.
The same response model has obvious limits. Boarding works when a vessel is in U.S. waters, willing to receive federal personnel, and not in motion at the time. None of those conditions hold for most of the global tanker fleet, which sails under flags of convenience and across jurisdictions where the U.S. has no boarding authority.
Attribution remains preliminary. The U.S. is looking into whether Iran was behind the compromise, per CBS, and the agencies have not named a culprit. The Cybersecurity and Infrastructure Security Agency has separately characterized recent Iran-linked intrusions as "opportunistic," a term that signals probing rather than coordinated attack (ABC News). A U.S. and Israel-led war against Tehran earlier in 2026 reportedly killed Iran's supreme leader in February. Since then, Iranian-linked hackers have struck the medical device maker Stryker, Los Angeles mass transit, and more than 100 U.S. water facilities, a campaign the tanker compromise now extends into a new domain.
The August 21–24 window stands as a precedent either way. Confirmed or not, a Coast Guard visit is now the default U.S. response to a tanker whose networks have been taken over at sea, and the global shipping industry will read it that way.