
US Coast Guard and FBI teams boarded two foreign‑flagged vessels in the Gulf of Mexico on Aug. 21 and Aug. 24 after intelligence indicated that hackers had penetrated their navigation and engine‑control systems.
The Coast Guard said that "foreign cyber actors" were involved but offered no names, and the FBI cited "indications of network compromise" as the trigger for the boarding. Neither agency released further details, and the U.S. Cybersecurity and Infrastructure Security Agency has yet to comment.
Dryad Global CEO Corey Ranslem confirmed that one of the ships was the Liberian‑flagged VL Prosperity, which is currently anchored in waters off Galveston, Texas, according to LSEG and MarineTraffic data. Liberia’s flag registry has not yet responded to requests for comment.
Iranian state‑run Mehr reported on Aug. 20 that the VL Prosperity suffered a "major cyberattack" while transiting the Strait of Gibraltar. An unnamed crew member said the attackers disabled the ship’s communications, reduced engine‑cooling flow, increased engine speed, and shut down its fuel and oil tanks, leaving the vessel adrift for 30 hours.
Ranslem warned that such attacks are technically easy to carry out and that maritime operators should expect more incidents in the near future. The Coast Guard has opened an investigation and is coordinating with the FBI and international partners to identify the perpetrators. Investigators are working to pinpoint the hackers and assess the threat to other vessels.