Coast Guard and FBI board tankers in Gulf after cyber compromises
The August boardings are the first publicly confirmed offshore cyber investigations of foreign-flagged commercial vessels, testing the Coast Guard's post-2024 executive-order posture.
TL;DR
The Coast Guard and FBI boarded two foreign-flagged tankers in the Gulf of Mexico on Aug. 21 and Aug. 24 after indications that both vessels' networks had been compromised. The joint statement cited no operational disruption or environmental harm. The boardings follow a 2024 executive order that gave the Coast Guard additional cyber-incident response authority and initiated rulemaking for maritime cyber reporting requirements, authority now being exercised in live operations against vessels carrying oil and natural gas, reportedly with Iran as an investigative focus.
The boardings combined Coast Guard law enforcement, Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators, a mix that signals the investigation wasn't a routine port-state inspection but a coordinated search for compromise on both IT and OT systems. The agencies called the cooperation of the captain, crew, and shore-side corporate staff "critical."
That cooperation isn't a given. Foreign-flagged commercial vessels operate under flag-state jurisdiction, and U.S. offshore boarding authority depends on the specific legal basis invoked, port-state control, customs enforcement, or a security-related justification. The joint statement doesn't specify which authority was used here, but the presence of armed law enforcement and FBI cyber operators suggests something beyond a standard safety inspection.
What the GAO saw coming
GAO published two reports in early 2025 that frame the gap these boardings are trying to fill. In January, GAO-25-106953 found that DHS had not developed objective, measurable performance goals for its maritime cargo security approach (1). In February, GAO-25-107244 reported that the Coast Guard cannot readily access complete cybersecurity-specific inspection data from its own system of record, the Marine Information for Safety and Law Enforcement database (6). That second report named China, Iran, North Korea, Russia, and transnational criminal organizations as the top cyber threats to the Maritime Transportation System.
So the service is mounting armed cyber boardings while, by GAO's account, it still can't pull a complete spreadsheet of its own cybersecurity deficiency findings. That isn't necessarily contradictory (operational tempo and administrative systems move at different speeds) but it's the kind of tension that becomes a problem when an incident crosses from investigation to consequence.
The EO and what it changed
Biden's February 2024 executive order gave the Coast Guard authority to respond to maritime cyber incidents and started a rulemaking to impose cyber reporting requirements on the sector (3). These August boardings are the first publicly acknowledged offshore exercises of that response authority. Whether the investigation yields enforcement action, rulemaking precedent, or simply intelligence on how adversaries are compromising vessel networks remains open, neither agency has said what the boardings found.
Published ·Deep Fathom