Published: · Region: Global · Category: cyber

U.S. Probes Cyberattacks on Oil Tankers Near Gibraltar, Raising New Fears for Maritime Energy Flows

U.S. investigators say at least two foreign oil and LNG tankers bound for American ports were hit by cyberattacks while sailing past the Strait of Gibraltar in August, compromising their IT and operational systems. The probes point to a new kind of chokepoint risk, where energy supplies can be targeted digitally long before tankers reach U.S. waters.

Two tankers carrying oil and liquefied natural gas to the United States arrived in the Gulf of Mexico this summer with more than routine paperwork for port officials. According to U.S. authorities, the ships had been hit by cyberattacks while transiting the narrow Strait of Gibraltar, raising fresh concern that hackers are learning how to reach into the control systems of large commercial vessels.

Officials say at least two foreign‑flagged tankers were targeted in August while passing through the strategic chokepoint linking the Atlantic and the Mediterranean. The attacks breached both operational systems, which help run the ship, and IT networks, which manage data and communications. When the vessels later docked near the U.S. coast, specialized teams from the Coast Guard and the FBI boarded to inspect the damage and gather evidence.

So far, there is no public attribution of who was behind the intrusions or what their precise objective was, and no reported accidents or spills linked to the incidents. But the fact that operational technology was compromised — not just office computers — is what alarms maritime security officials. Software that touches navigation, engine management, or cargo handling can, in the wrong hands, be used to shut a ship down, misdirect it, or push equipment into unsafe modes.

For the crews aboard, that translates into the possibility of losing power or steering in some of the world’s busiest sea lanes. For shipping companies and insurers, it adds another layer of risk to routes that already carry geopolitical weight. The Strait of Gibraltar may not be as synonymous with energy tension as Hormuz or Bab el‑Mandeb, but it is a critical artery for tankers moving between Europe, North Africa, the Americas, and beyond.

The incidents come at a moment when energy markets and naval planners are already on edge. Threats to shipping from state and non‑state actors in the Middle East, together with sanctions regimes and attacks on undersea cables, have reminded governments that maritime infrastructure is not automatically safe. Cyber operations against tankers push that vulnerability into a new domain, one where damage can be inflicted without a single small boat or missile ever approaching the hull.

Strategically, the stakes are not limited to the handful of ships involved. If attackers demonstrate a reliable way to penetrate operational technology on commercial vessels, they gain leverage over global supply chains at a fraction of the cost of traditional naval power. A disrupted voyage doesn’t have to sink a ship to matter; it only has to delay cargoes, force suspicious ports to deny entry, or prompt insurers to reprice routes.

For energy buyers, especially in the United States, the immediate impact of the August attacks appears contained. There are no indications yet of significant delivery delays or market‑moving disruptions tied directly to these cases. But they plug into a wider anxiety: that oil and LNG supplies can be squeezed not only by wars, sanctions, or blockades, but by a handful of well‑timed keystrokes against under‑defended ships.

The lesson is stark. Maritime chokepoints don’t need mines or missiles to become risky; a compromised navigation console in a narrow channel can have many of the same effects in slow motion. The Gibraltar incidents show that cybersecurity on tankers is now as much a part of energy security as pipeline routes or naval escorts.

What happens next will depend on what U.S. investigators find. Clear attribution to a state or organized group would push the issue into diplomatic and potentially military channels, especially if a pattern appears across more vessels. In the meantime, watch for new Coast Guard directives to the shipping industry, changes in port state control inspections focused on cyber hygiene, and whether charterers begin quietly favoring operators who can prove their operational technology is locked down.

Sources