US tracking cyberattacks on nearly 20 ships worldwide
US Coast Guard and federal agencies monitoring vessels targeted in late August cyberattacks; two boarded in Gulf of Mexico.
What to know
- Nearly 20 shipping vessels worldwide are under US government tracking for cyberattacks; two were boarded in the Gulf of Mexico on August 21 and 24 to secure compromised networks.
- Hackers did not achieve control of the targeted ships; no operational disruptions, physical dangers, or environmental impacts have been reported.
- Maritime cyber incidents are accelerating, with malware primarily introduced via storage devices; aging ship systems lack easy update mechanisms, creating persistent vulnerabilities.
- The US Coast Guard, FBI, and DHS are coordinating the response and requiring advance notice from vessel operators planning US port entry.
“In the case of more than half of the attempted intrusions that CyberOwl detected on the vessels it tracks, malware had been introduced to the vessels' computers through storage devices”
CyberOwl, Maritime cybersecurity firm · Orlando Sentinel ↗
US Coast Guard Maritime security authorityCybersecurity and Infrastructure Security Agency (CISA) Federal cybersecurity agencyAntonio Cassidy Director of services, CyberOwl maritime cybersecurity firmMaria Bartnes Cybersecurity research program director, DNV
How it unfolded 1 development · click the chart to see its coverage articles
-
1
“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”
— US Coast Guard -
5 outlets first by Denver Post, 6d ago · also Baltimore Sun, Mercury News, Orlando Sentinel, Straits Times · read ↗
-
-
background
US Coast Guard boards second compromised vessel — The Coast Guard boarded a second inbound foreign-flagged commercial vessel in the Gulf of Mexico to ensure integrity of its operational and information technology systems following network compromise indications.
-
background
US Coast Guard boards first compromised vessel in Gulf of Mexico — The US Coast Guard boarded an inbound foreign-flagged commercial vessel in the Gulf of Mexico following indications that its networks were compromised. The boarding was conducted to mitigate cybersecurity threats.
-
background
Multiple commercial vessels targeted in cyberattacks — Several commercial vessels were targeted in potential cyberattacks in late August. According to CISA officials, hackers did not appear to have taken control of the targeted ships themselves, though their networks showed signs of compromise.