U.S. Probes Cyberattacks on Oil and LNG Tankers Hit Near Strait of Gibraltar
U.S. authorities are investigating suspected cyberattacks on at least two foreign oil and LNG tankers that were compromised while passing through the Strait of Gibraltar in August, then inspected by Coast Guard and FBI teams in the Gulf of Mexico.
U.S. authorities are investigating suspected cyberattacks on at least two foreign oil and liquefied natural gas tankers that were compromised on their way to American ports, raising concerns about hackers targeting ships that move critical energy cargoes.
Officials say the vessels were attacked while transiting the Strait of Gibraltar in August, a narrow passage between the Atlantic and the Mediterranean. After reaching the Gulf of Mexico, the tankers were boarded and inspected by U.S. Coast Guard and FBI teams.
According to the initial reporting, the intrusions affected both operational technology systems, which handle steering, propulsion, and other ship controls, and traditional IT networks. There have been no public reports of collisions, groundings, spills, or other visible incidents linked directly to these attacks, and the tankers’ identities and flags haven’t been disclosed.
Even so, on‑scene inspections by U.S. teams signal how seriously officials view the possibility of hackers reaching into bridge controls, engine management systems, or cargo handling software from afar. For crews, tampered navigation data or falsified sensor readings could turn an ordinary passage through busy sea lanes into a dangerous guesswork exercise.
For shipowners and charterers, cyber risk now feeds into insurance, compliance, and scheduling. If authorities decide a compromised vessel isn’t safe to enter port, operators face delays and extra scrutiny that can ripple through delivery schedules for oil and gas buyers.
Strategically, the suspected attacks show how cyber operations can reach into the physical infrastructure of global energy trade. The Strait of Gibraltar is a key route for some cargoes heading to Europe and the Americas. Demonstrating that malware can ride along with those flows is a way to test how governments and regulators respond when shipping, energy security, and cybersecurity collide.
So far, the U.S. hasn’t publicly blamed any actor, leaving open whether this is espionage, criminal extortion, or preparation for potential future disruption. That ambiguity keeps a wide range of suspects in play, from profit-driven ransomware gangs to state-linked groups probing how far they can go without provoking a broader response.
The next clues will likely come from policy rather than attribution. Broader advisories from U.S. agencies to the shipping and energy sectors, tougher cyber requirements from insurers and classification societies, or a public decision to name a responsible actor would all signal that these incidents are being treated as more than isolated technical glitches.
Sources
- OSINT