TL;DR — too long, didn’t read

Two tankers bound for the United States were boarded by the Coast Guard and the FBI in August, after signs that somebody had been inside their networks, and it became public knowledge in the middle of September. An LNG carrier's suspected incident reached the public record because her crew told a classification society. And the largest number published about maritime cyber this week, 120 million attacks on one port in one month, is the one that tells you least. No owner of any affected ship has said anything at all.

Panama: registration is open, and this is the last issue before it

Two issues ago this newsletter said registration for the Panama exercise "is opening on their side now", and it had not. Last issue said so plainly and promised to report the moment anything changed. It has changed: registration is open.

The conference at the Universidad Marítima Internacional de Panamá runs on Thursday 24 September, and our session is the first thing after the opening, from 08:40 to 10:10. The full-day exercise is on Friday 25 September, 09:30 to 15:30, at the same university. No technical background is needed and places are limited by the size of the room. To register, write to [email protected] or call 520-4071.

If you are in the region and this is your work, this is the last issue that can be of any use to you about it.

Three things that matter this week

The Coast Guard went aboard, and found malicious code

On 21 August 2026, US Coast Guard boarding teams went aboard the VLCC VL Prosperity off the Texas coast, as she approached Galveston. Three days later, on 24 August, a second vessel was boarded elsewhere. Neither boarding was announced at the time. Both became public on 16 September, in a wave of reporting that included Rear Admiral Amy Grable, commander of US Coast Guard Cyber Command, speaking on the record to CBS News.

VL Prosperity is a Liberian-flagged crude carrier, roughly 333 metres long, capable of holding around two million barrels. She had loaded Saudi crude at Sidi Kerir, Egypt, in late July, and suffered an incident around 7 August while transiting the Strait of Gibraltar. She continued to Texas. The second vessel has not been named by the Coast Guard, and outlets disagree on what she even was: gCaptain describes an LNG carrier, others an oil or energy tanker. Nobody official has settled the question.

Grable described what her teams found in plain terms. "They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity," she told CBS. Her concern was less the IT itself than what it touches: "The real thing we're concerned about is those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel." On the malware, she was unimpressed: "Not necessarily that sophisticated. There is malicious source code that people can get their hands on." A Coast Guard spokesperson, unnamed, called the operation "a comprehensive cyber security boarding and investigation" and said there were "no reports of operational disruptions, vessel instability, physical danger to crew or environmental impact."

Nobody in an official capacity has attributed either intrusion. Grable said only that the US is investigating whether the two incidents are connected, and whether Iran or another foreign adversary was behind them; that is a question under investigation, not a finding. Iranian state media, via the Mehr News Agency, had already claimed in August that hackers reached VL Prosperity's propulsion, navigation and cargo systems and knocked out her communications for 30 hours. Take that as an Iranian state broadcaster's claim, not as anything confirmed by anyone else.

Bloomberg reported on 16 September, citing officials who spoke anonymously because they were not authorised to discuss it publicly, that nearly 20 vessels worldwide are being tracked for cyber threats. Lay the dates from this case side by side and the gap is the story: incident around 7 August, boarding on 21 August, public in the Western press on 16 September. Forty days. The earliest public account we have found came from Iranian state media on 20 August, thirteen days after the incident, before any Western outlet carried it and before the ship was boarded.

That gap has a mundane explanation. Since 16 July 2025, US-flagged vessels, MTSA facilities and OCS facilities have carried a mandatory duty under 33 CFR Part 101 Subpart F to report a cyber incident to the National Response Center. Foreign-flagged vessels are not subject to it; they get Port State Control scrutiny instead, which inspects what is in front of it rather than waiting to be told. VL Prosperity and the second vessel were both foreign-flagged and both US-bound. Nobody aboard either ship was obliged to report anything to anyone. Boarding was the only mechanism left that could put this on the record at all.

What to do: Ask your DPA or ISM manager, this week, one direct question: if this ship suffers a suspected cyber incident inside US waters, who is legally obliged to report it, and to whom? For a foreign-flagged vessel, under the US cyber rule specifically, the answer is nobody, whatever your flag state and your class society may separately require. Port State Control can still stop you at the pier and find out anyway, on its own schedule, not yours. Get the internal chain written down before that happens, and make sure it names a person, not a department.

Test your response: Your foreign-flagged VLCC crosses into US territorial waters when the IT officer flags an anomaly consistent with malicious activity; nothing looks physically dangerous yet. Subpart F does not require you to report anything, because you don't fly the US flag. Do you tell anyone anyway, before a boarding team finds it for you, and if so, whom do you tell? USCG Cyber Drill: The Final Rule Reality Check →

An LNG carrier's crew put a cyber incident on the record, not the owner

On a voyage from the US Gulf coast to Italy, the LNG carrier Vivit Africa LNG suffered a systems failure her crew suspected was a cyber attack. She is a 2023-built, Liberian-flagged carrier, IMO 9950105, operated by South Korea's H-Line Shipping and on time charter to Vitol. She had loaded at the Cameron LNG terminal in Louisiana, bound for Rovigo, Italy.

She did not turn back, whatever several outlets reported. She diverted, away from Rovigo and towards Algeciras, Spain, instead. The distinction matters: turning back means retreating the way you came; diverting means finding a different destination while still moving forward. One is a retreat, the other a decision made under uncertainty about what still works.

The crew reported the failure as a suspected cyber attack to Korean Register, the vessel's classification society. Whether they also told the operator or the charterer at that point is not on the public record. The Italian Coast Guard later confirmed that a systems malfunction had occurred. It did not confirm a cyber cause; that remains suspected, not established. This is a different ship, a different sea and a different time from the two tankers boarded off the US coast this week, and nobody has suggested a link between the cases.

What stands out is who spoke first. Not the owner, not the charterer, not a flag administration. A crew, mid-voyage and uncertain what had gone wrong, told the body whose surveyors cover those systems.

What to do: Ask your master and chief engineer this week whether they know they can report a suspected cyber incident directly to your classification society, mid-voyage, without waiting for the office to decide how to frame it. Then ask what they think would actually happen if they did. If the honest answer is "we'd call the office first and see what they want us to say", that is your gap to close, not theirs.

Test your response: Mid-Atlantic, your bridge team notices navigation and propulsion behaving oddly at the same time, and the office has not called back. Nobody has told you it's safe to say the word "cyber" to anyone outside the company. Who do you call first, and what do you say? Hormuz Haze: The Tanker That Couldn't See, Couldn't Stop, Couldn't Call →

A port counted 120 million attacks, and the number stopped there

Gene Seroka, executive director of the Port of Los Angeles, told Bloomberg, in remarks reported on 17 September, that the port had "foiled around 120 million cyberattacks" in August 2026. It was a comment in a media interview, not testimony to a hearing or a line in a filing.

Nobody has published what the number actually counts. The only description on offer is that the port's cybersecurity team identified "intrusion, network exploitation, credential harvesting and malware attacks, among other efforts". There is no methodology attached to that sentence, and none has surfaced since. What counts as one of the 120 million is left to the reader's imagination.

There is a genuine historical comparison to make, because Seroka has given a figure like this before: in July 2022 he said the port was "bombarded with around 40 million attacks each month". Four years on, whatever is being measured now reads roughly three times larger, with no stated change in method to explain the jump.

None of this makes Seroka a bad witness. The Port of Los Angeles is a genuine target, and a cybersecurity team logging that volume of automated probing at its perimeter is doing real, unglamorous defensive work. The problem is not what he said. It is what the number becomes once it leaves the interview: a figure that sounds like a battle won, when it almost certainly aggregates the same automated scanning that hits every internet-facing address on the planet, ship or shore, all day, every day.

Set it against the rest of this week's reporting and the contrast writes itself. A number this large tells you nothing about any specific ship. Two quiet facts, a boarding off Texas and a diversion off Italy, tell you a great deal about two specific ships. That is the wrong way round for anyone trying to work out where the actual risk sits.

What to do: The next time a port, a vendor or a briefing slide cites a headline count of attacks blocked, ask one question before it goes into a board paper: what does a single attack consist of, and would one automated scan sweeping every address on the network count as one event or as thousands? The honest answer, most of the time, is that nobody kept the count broken down that way, which tells you the number was never built to survive the question. Compare it, if you can, to any earlier figure from the same source; a jump with no stated change in method, like this week's figure against Seroka's own 2022 one, is a gap in the method, not a trend.

Test your response: A colleague forwards you the "120 million cyberattacks" line and asks whether your own port or terminal faces the same risk. You have no equivalent number for your own operation. What do you tell them you actually know, as opposed to what the headline implies you know? CMA CGM: Ransomware in the Container Kingdom →

A correction, and four names revisited

Last issue counted the Philippine Ports Authority among four maritime organisations that had been named on leak sites and said nothing, and put a number on it: nine days of silence. That was wrong, and it was wrong in a way worth explaining.

The Philippine Department of Information and Communications Technology had already addressed it on 9 September, six days before we published, describing the report as a false positive with no system compromise and no data breach. We measured the silence by querying our own collection of sources, which does not gather the Philippine government's own announcements, and reported an absence in our collection as an absence in the world.

The other three are unchanged. TEC Container, named 26 August, and Globalport Terminals, named 27 August, are now at four weeks. AMPTC, named 1 September, is at three. Nothing from any of them.

On last week's port: Tanjung Pelepas resumed operations on 15 September, and has said nothing further about what the incident was. The group that listed it has published nothing since.

In case you missed it

The House Transportation and Infrastructure Committee approved H.R. 7625, the Marine Transportation System Cybersecurity Budget and Evaluation Report Act, by voice vote, together with a substitute amendment offered by Representative Addison McDowell. The bill directs the Government Accountability Office to review, within 270 days of enactment, whether the Coast Guard has the resources, workforce and tools for its role as co-Sector Risk Management Agency for the marine transportation system. It now advances toward a floor vote. Reporting puts the markup on 15 September; the committee's own release says 16 September, and we could not resolve which.

Read alongside this week's boardings, the sequence over fourteen months is worth stating again: the rule came into force, the office was created, the career path was defined, and now Congress is asking whether the agency enforcing it can afford to.

Coming up

  • 10th NMIOTC Conference on Cyber Security in Maritime, Chania, 23–24 September, and CS4CA Europe, London, the same two days. Still an unfortunate clash if you were considering both.

  • World Maritime Day, Panama, 24–25 September. As above. The Thursday is the World Maritime Day programme; the exercise runs on the Friday, 09:30 to 15:30, and registration goes through UMIP.

  • Maritim Cyber Security, Ålesund, 29 September and ShipIT, Athens, the same day. Both dedicated maritime cyber events, both single-day, at opposite ends of Europe.

Full calendar, with cyber tracks flagged: https://mc3.maritime-ogmios.tech

Number of the week

  • 40 days — from the incident aboard VL Prosperity, around 7 August in the Strait of Gibraltar, to the day the Western press could report it, 16 September. The ship was boarded on 21 August, in between. For four issues this newsletter has measured silence in weeks; here the measurement runs to nearly six, and what ended it was not the owner but officials briefing a reporter without putting their names to it.

Scuttlebutt

Unconfirmed signals from open-source and regional channels we monitor. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.

Inland and Offshore Contractors, listed by the Qilin group on 18 September. The listing itself gave us nothing: the description field was empty. The victim domain, iocltt.com, resolves to a Trinidad and Tobago contractor of about thirty years, providing offshore support and marine transport in the Caribbean with a fleet running from 45 to 230 feet. That is a maritime nexus established from the domain, which is the only part of a leak-site entry that is not written by the attacker.

Everything else about it is the attackers' claim. No confirmation of a breach, no statement from the company, nothing about what was allegedly taken.

Resource of the week

1-800-424-8802

The National Response Center. Under 33 CFR 101.305 an owner or operator must report suspicious activity and breaches of security to that number without delay, and since the Coast Guard's cybersecurity rule came into force on 16 July 2025, reportable cyber incidents go there too, immediately on discovery. It is a phone number, it is staffed, and it is the whole mechanism.

We are giving it as the resource of the week for a reason that is slightly uncomfortable. The duty attaches to US-flagged vessels, MTSA-regulated facilities and outer continental shelf facilities. Both ships boarded last month were foreign-flagged. Nobody aboard either of them was obliged to call this number, and as far as the public record shows, nobody did.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"Cyber-worthiness in Shipping: Law, Regulation and Practice", by Furkan Dogan, 2026.

It takes the doctrines a maritime lawyer already knows, seaworthiness, due diligence, liability, and asks what each of them becomes once a vessel's systems can be reached from outside. The answer it proposes, cyber-worthiness, is a legal test rather than a technical one.

Relevant this week because the awkward question underneath every story here is not technical either. It is who owed a duty to whom, and what follows when the answer is nobody.

One disclosure, because this is the week for it

A chapter I wrote is out. "Maritime security and cybersecurity" is chapter 14 of Digital Transformation in Maritime Transportation and Logistics, edited by Michele Fiorini and Dorota Książkiewicz, published by the IET. Twenty-three pages on why cyber risk behaves differently at sea, what the regulations actually require, and three incident cases.

Two things you should know before you decide whether to care. I wrote it, so I am not a neutral party about it. And our books catalogue earns an affiliate commission if you buy through it, on this title as on every other one there. Neither of those makes the chapter better or worse; they are simply things you are entitled to know before I mention it in my own newsletter.