A supertanker a thousand feet long, carrying roughly two million barrels of crude oil, left a terminal in Egypt at the beginning of August bound for Texas. About a week into the voyage, as it passed through the Strait of Gibraltar, something went wrong with its network. Two weeks after that, a specialized team of FBI and Coast Guard cyber personnel boarded the vessel in the Gulf of Mexico and spent four days going through its systems.
They found evidence of malicious cyber activity. A second vessel, a liquefied natural gas carrier, was boarded three days later for the same reason.
Nobody was hurt. Nothing spilled. The ships kept operating, the crews cooperated fully, and the supertanker has since been cleared to resume normal service. But buried in the Coast Guard’s explanation of what they were actually worried about is one sentence that describes, with uncomfortable precision, a risk sitting in a great many ordinary businesses — including, quite possibly, yours. We’ll get to that sentence. First, a correction that matters.
About the headline you probably saw
This story is circulating on social media under a graphic reading something like “cyberattacks hit U.S. tankers in Galveston port.” That framing is wrong in two specific ways, and since being accurate is the entire reason to read anyone’s coverage of these stories, let’s fix it:
- They weren’t U.S. tankers. The supertanker is Liberian-flagged and managed by a South Korean company. The second vessel is also foreign-flagged. They were bound for the United States, which is why American agencies got involved.
- Nothing happened in Galveston port. The suspected intrusion occurred near the Strait of Gibraltar — on the other side of the Atlantic. Galveston was simply the destination. The boarding happened at sea, in the Gulf of Mexico.
Those distinctions aren’t pedantry. “Cyberattack in a Texas port” and “a foreign ship’s network was compromised mid-ocean and American investigators boarded it before it arrived” are different events with different implications. This is the second time in a week we’ve had to unwind an accurate news story from an inaccurate graphic wrapped around it, which is itself worth noticing: the headline someone pasted on top of a news clip is not the news. If a claim matters enough to act on, it’s worth thirty seconds to find the underlying report.
What’s confirmed, and what’s being claimed
Here’s the record as it stands, from the joint FBI and Coast Guard statement and subsequent reporting:
- Two boardings. August 21 and August 24, both in the Gulf of Mexico, both following indications that a foreign-flagged commercial tanker’s network had been compromised. Multiagency teams including Coast Guard law enforcement, a vessel inspector, a Coast Guard Cyber Protection Team, and FBI Cyber personnel.
- Malicious activity was found. The commander of Coast Guard Cyber Command said investigators assessed the information technology and other systems aboard and did find malicious cyber activity.
- No harm resulted. The official statement is explicit: no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts. Investigators found no evidence the ship had become unsafe to navigate.
- The response continued after the boarding. Investigators hunted for malware and worked through the IT systems, and the Coast Guard said it plans to provide the vessel’s owner with recommendations for patching vulnerabilities. The tanker was subsequently cleared for normal operations.
Now the claimed part. Iranian state media reported that hackers had reached the ship’s propulsion, navigation, and cargo systems and knocked out its communications for 30 hours. That is a claim from a state news agency, not a finding by U.S. investigators. The Coast Guard has not publicly attributed the incidents to anyone, and officials have said they’re investigating whether the two events are connected and whether a foreign adversary was responsible. We’re reporting the claim because it’s part of the public record and because the specific systems it names matter to the lesson below — but we’re labeling it clearly as a claim, and we take no position on attribution or on any of the geopolitics attached to it. That’s for investigators to determine and for others to debate.
The sentence that matters
Here’s the part worth your attention. Asked what actually concerned her about these incidents, the Coast Guard Cyber Command commander said the real worry was those IT systems being connected to other systems on the ship that control propulsion, navigation, and other functions critical to the vessel’s safety.
Read that again with your own business in mind, because it’s a description of a general condition, not a nautical one.
Every organization now runs two kinds of technology. There’s information technology — the email, the files, the computers people type on. And there’s operational technology — the systems that make physical things happen. On a ship that’s engines, steering, and cargo handling. In a factory it’s the machinery. In a building it’s the HVAC, the door locks, the elevators. In a restaurant it’s the walk-in cooler’s temperature controller and the point-of-sale. These two worlds used to be entirely separate, often not even wired together. Now they almost always share infrastructure, because connecting them is genuinely useful — you get remote monitoring, efficiency data, predictive maintenance, the ability to check on things from your phone.
And that connection is the whole ballgame. The reason a compromised email system on a ship is frightening isn’t the email. It’s that the email system might be able to reach the systems that steer the ship. An intrusion that would be an inconvenience in an office becomes a safety event when the office network touches the machinery. The question that matters for any business is therefore not “could someone get into our computers?” — assume yes — but “if they did, what physical things could they then reach?” Most owners have never asked it, and almost none could answer it from memory.
A supertanker is, in IT terms, a small business
It’s tempting to file this under “critical infrastructure, not my problem.” But look at the actual profile of the target and you’ll find something familiar.
A commercial tanker carries a crew of roughly twenty to twenty-five people. It has no dedicated IT department aboard. Its network was installed by contractors and is maintained remotely, often by third parties. It’s full of connected equipment from a dozen different vendors, some of it old, much of it rarely updated because updating it requires a specialist who isn’t there. It operates far from help. Decisions get made by people whose expertise is running the operation, not securing the network.
That is the exact profile of a small business. A tanker is a floating facility worth hundreds of millions of dollars with the IT maturity of a twenty-person company — which is why the lessons transfer so cleanly. The scale of the asset has almost nothing to do with the sophistication of its defenses, and attackers know it.
Regular readers will recognize this as the same thread running through several stories we’ve covered this year: a small power plant reached through a wind farm, thousands of industrial controllers left reachable from the internet, community water systems attacked because they were lightly defended. The soft target isn’t the one that gets overlooked — it’s the one that gets chosen. A ship at sea is simply the newest version of it.
Your business has operational technology too
You may not think of yourself as having any. You almost certainly do. Walk through your operation and count the things that are connected to a network and also make something physical happen:
- Security cameras and alarm systems you can view from your phone.
- Door locks and access control — the badge reader, the keypad, the buzzer.
- HVAC and building systems, including the smart thermostat somebody installed to save on energy.
- Refrigeration and temperature monitoring — and if you’re a restaurant, a grocer, a florist, or a medical practice, that equipment is protecting inventory you cannot afford to lose.
- Point-of-sale terminals, kitchen displays, scales, and printers.
- Shop and production equipment — CNC machines, diagnostic tools, lifts, anything a vendor can dial into remotely to service.
- Irrigation controllers, gate openers, lighting systems, well pumps — the outdoor gear nobody thinks of as a computer, which is exactly why nobody has updated it since installation.
Now the question: how many of those sit on the same network as the computer where your staff open email? For most small businesses, the honest answer is all of them, because there’s one network and everything went on it. That means the distance between “somebody clicked a bad link in the office” and “somebody can reach the walk-in cooler” is zero. That’s the identical structural problem the Coast Guard was describing — just with lower stakes and a shorter cable run.
What to actually do about it
None of this requires you to disconnect anything or give up the convenience that made you connect it in the first place. It requires knowing what’s connected to what, and putting walls in sensible places:
- Make the list. Write down every device in your business that’s on the network and does something physical. You cannot protect equipment you’ve forgotten you own, and this list is almost always longer than the owner expects. Include the things a vendor installed and told you not to touch.
- Separate the networks. Your operational equipment should not sit on the same network as email, web browsing, and guest Wi-Fi. This is called segmentation, and it’s the single most effective control here: it means a compromise on the office side can’t simply walk over to the machinery. It’s also the thing most small networks were never set up to do.
- Change every default password on that equipment. Cameras, controllers, thermostats, POS gear. Factory credentials on connected devices are among the most exploited things on the internet, and they’re free to fix.
- Close off internet access the equipment doesn’t need. A great deal of operational gear is reachable from the open internet with no business reason, usually because that was the easiest way to set up remote access years ago. If it doesn’t need to be reachable, it shouldn’t be.
- Audit vendor remote access. Which outside companies can dial into your equipment, and how is that connection secured? Every one is a door into your operations held open by somebody else’s security practices.
- Update the boring devices. The camera recorder and the controller in the closet receive security updates too, and almost nobody installs them. When a device is too old to receive updates at all, that’s a replacement decision, not a maintenance one.
Worth asking about your own business: Could you list every networked device that makes something physical happen in your operation? * Is your operational equipment on the same network as email and guest Wi-Fi? * If someone got into a computer in your office tonight, what physical systems could they reach from there? * And which outside vendors can connect into your equipment right now?
The good news is real, and it’s the point
We want to end on what actually happened here, because it’s genuinely encouraging and it contains the most useful idea in the whole story.
Malicious activity was found on a vessel carrying two million barrels of oil — and nothing bad happened. No disruption, no danger to the crew, no environmental damage, no loss of control. Somebody noticed something was wrong, a competent team came and looked, they assessed what had been touched, they went hunting for what shouldn’t be there, and they handed the owner a list of things to fix. The ship went back to work.
That’s what the space between compromised and damaged is for. Being breached is not the same as being harmed, and the gap between them is where all the useful work happens — if somebody notices, and if somebody responds. The businesses that come through incidents intact aren’t the ones nobody ever tried; they’re the ones where the intrusion got caught early, the damage was contained by walls that were already in place, and someone knew what to do next.
Building those walls before anything happens is exactly what our environment review is for. We map every connected device in your business, find the operational equipment sitting on the same network as your email, identify what’s exposed to the internet or reachable by a vendor, and help you put separation where it belongs — so that a bad click in the office stays a bad click in the office, instead of becoming a problem with the machinery that runs your business. A team boarded a ship in the Gulf of Mexico to answer the question of what an intruder could reach. You can answer it in your own business without anyone boarding anything. Let’s take a look.
Sources: Joint FBI and U.S. Coast Guard statement (September 16, 2026); Associated Press; Bloomberg; CBS News interview with the commander of U.S. Coast Guard Cyber Command; The Wall Street Journal; gCaptain; and additional reporting, September 2026. The vessels involved were foreign-flagged and bound for the United States; the suspected intrusion on the first occurred near the Strait of Gibraltar, not in a U.S. port. Officials reported no operational disruptions, vessel instability, physical danger to crews, or environmental impacts, and the first vessel has been cleared for normal operations. Claims regarding access to propulsion, navigation, and cargo systems and a 30-hour communications outage originate with Iranian state media and have not been confirmed by U.S. investigators, who have made no public attribution. This article takes no position on attribution.













