DEV Community

Max Bayern
Max Bayern

Posted on Originally published at ot-cyber.de

Tanker Hack: What Access to the Propulsion System Means for OT

On 21 August 2026, the US Coast Guard and the FBI boarded a crude oil tanker. This post is a short English adaptation of my German original and looks at what the incident means for OT, plants and machinery.

What happened

The vessel is the VL Prosperity: 333 meters long, carrying roughly 2.3 million barrels of crude oil, flying the Liberian flag. The trigger was information that "foreign cyber actors" had compromised the onboard networks. The Coast Guard confirms "malicious cyber activity". On 2 October 2026, Bloomberg reported, citing US officials, that investigators had found evidence of temporary access to the propulsion system.

What I want to state explicitly:

  • The FBI says there are currently no reports of an operational disruption, a danger to the crew or environmental damage.
  • It is not proven that the attackers changed anything on the propulsion system.
  • The dramatic accounts (throttled cooling, increased engine speed, 30 hours of radio outage) come from Iranian state media and are unconfirmed.
  • The engine room images circulating alongside them are fakes, according to an analysis by Cydome.

All confirmed facts, open questions and assessments with sources are in our incident situation report on the VL Prosperity (in German).

Why this is not just a maritime topic

A modern tanker is a floating plant: propulsion, auxiliary systems and cargo monitoring, all connected via controllers and networks. On top of that come satellite communication, remote maintenance by vendors and digital machinery monitoring. The Coast Guard names connectivity as the reason for the vulnerability: "When these vessels are highly connected, they're susceptible to cyber threats." The technical hurdle is "not necessarily that sophisticated".

Replace "ship" with "production line" and "satellite communication" with "remote maintenance router", and you get a fairly accurate description of how many connected production plants are built today.

If the path really led through the onboard IT all the way to the machine, the tanker shows what is possible then. Whether ship or filling line: if you don't know who can reach your controllers from the outside, you have already given up half of your control.

Five lessons for plants and machinery

I map them to the SANS Five ICS Cybersecurity Critical Controls.

  1. Know and control remote access (CC4, Secure Remote Access). On ships as in factories, vendors often have permanent access. Every access path should be inventoried, logged and enabled only when needed, via a jump host with MFA.
  2. Separate IT and the control level (CC2, Defensible Architecture). In an incident like this, a central question is whether the onboard IT was connected to propulsion and navigation. Every operator should be able to answer that question for their own plant.
  3. See what happens in the OT network (CC3, Network Visibility). It is not publicly known how long the attackers were in the system on board. Without detection in the OT network, this is also one of the most common open questions after an incident in production.
  4. Practice manual operation and restart (CC1, Incident Response). According to DNV, most ships have backup systems. In my view, these make the difference between an incident and a casualty. In production, the question is: do operations and maintenance know how to safely keep running or shut down without the control system?
  5. Take legacy systems seriously (CC5, Risk-Based Vulnerability Management). The new cyber requirements for ships (IACS UR E26/E27) only apply to newbuilds with a construction contract from 1 July 2024 – the VL Prosperity dates from 2015. Mechanical engineering is similar: the CRA applies to products newly placed on the market, while existing plants often keep running for many more years.

Lesson six: disinformation belongs in the incident plan

Fake images, unconfirmed accounts from state media, anonymous sources: in this incident, a large part of the reporting was hard to verify. Anyone who has to inform customers, authorities and press in a real emergency needs prepared statements and a clear separation between "confirmed" and "assumed". That is exactly why our incident situation reports work with a counted knowledge scale.

And what about AI?

According to a report by Anthropic from September 2026, an Iran-linked threat actor used AI to compile public data on US naval forces and known vulnerabilities in maritime VSAT terminals and industrial controllers. A connection to the VL Prosperity is not proven. But it shows how quickly attackers can assemble targets and weaknesses today – one more reason to focus on the five controls rather than on point solutions.

Practical takeaways

  • Inventory every remote access path to your controllers; use a jump host with MFA.
  • Be able to answer whether your IT network is connected to the control level.
  • Get visibility and detection in the OT network.
  • Practice manual operation and restart without the control system.
  • Plan for legacy systems that will keep running for years.
  • Prepare statements that separate "confirmed" from "assumed".

How we support

If you want to know which remote accesses point to your controllers, we start with an OT security consulting engagement or an OT asset inventory. For machine builders who build remote maintenance into their products, CRA as a Service is the right entry point. And if things are already on fire: OT incident response. To prepare maintenance and engineering teams, see Cyber awareness for maintenance and engineering.

Original (German): https://ot-cyber.de/blog/tanker-hack-was-der-zugriff-auf-den-antrieb-fuer-ot-bedeutet.html

Max Gilg is an OT cybersecurity consultant based in Rosenheim, Germany (OT-Cyber.de).

Top comments (0)