Published: · Region: Global · Category: cyber

Suspected Cyberattacks on Tankers Near Gibraltar Raise Alarms Over Energy Shipping Security

U.S. officials are investigating suspected cyberattacks on at least two foreign oil and LNG tankers that were hacked while passing through the Strait of Gibraltar and later inspected in the Gulf of Mexico. The incidents, which compromised both operational and IT systems, raise fresh questions about how safely global tanker traffic can move.

Two foreign‑flagged energy tankers crossed the Atlantic this summer carrying more than oil and liquefied natural gas. U.S. authorities say suspected cyberattacks hit at least two such vessels in August as they transited the Strait of Gibraltar, compromising both onboard operational systems and information‑technology networks.

When the ships reached the Gulf of Mexico, U.S. Coast Guard and FBI teams boarded them to inspect their systems, a sign of how seriously Washington now treats the risk of hackers reaching the controls of tankers headed for American ports. Officials have not publicly named the ships, their owners or the suspected perpetrators, but the intrusions were significant enough to trigger formal investigations.

Operational systems on a tanker include the controls that manage propulsion, steering and cargo handling. If compromised, those systems could in principle be manipulated to affect a ship’s course or the state of its cargo. Even if no such loss of control occurred here, the fact that attackers reportedly reached both operational and IT environments is a warning for crews and port states.

The Strait of Gibraltar is a narrow maritime chokepoint linking the Atlantic Ocean and the Mediterranean Sea, with heavy traffic from Europe, North Africa and the Middle East. An incident there involving a large tanker would have implications far beyond a single ship, from safety and environmental risks to delays and rerouting.

For the energy trade, the suspected hacks underline that security now depends not just on physical escorts and safe sea lanes, but also on the integrity of software and networks aboard individual vessels. A compromised tanker approaching busy port approaches is a danger to nearby ships and infrastructure and a potential leverage point for whoever is behind the attack.

Maritime and cyber‑security specialists have warned for years about growing digital threats to shipping. What investigators are now seeing in the Gulf of Mexico suggests those threats have moved from offices on shore directly onto the bridges and engine rooms of working tankers.

The next indications of how serious this episode becomes will likely come from any new Coast Guard rules on cyber inspections, public advisories describing the techniques used against these ships, and whether flag states or classification societies tighten their own requirements for software security on tankers.

Sources