US Probes Cyberattack on Energy Tankers Over Possible Iran Ties


One of the Journal reported that US authorities are investigating a possible Iranian connection to cyberattacks targeting two energy tankers in August heading toward American ports. A number of vessels were attacked as they passed through the Strait of Gibraltar before proceeding towards Texas. These vessels were the oil tanker VL Prosperity and the liquefied petroleum gas carrier Kohaku which were targeted. 

At the time of the incident, the VL Prosperity was transporting more than two million barrels of oil from Egypt to Galveston, Texas. The Kohaku was also on its way to Texas where it was scheduled to load liquefied petroleum gas. Following the arrival of the vessels in the Gulf of Mexico, a specially trained cyber response team led by FBI personnel boarded both. 
The Coast Guard conducted several days of assessments of the incidents and checked to ensure that the vessels could continue operating safely after they discovered signs of a compromise of their information technology and operational systems. According to reports published in August, hackers gained access to the engine-room systems of the VL Prosperity and interfered with several engine functions, including cooling, speed, fuel, and engine oil. 
There was no claim of responsibility from any group, and the reported details were unable to be independently verified. Later on, the vessel's manager confirmed that US authorities examined the tanker's cybersecurity before clearing it for normal operations. This incident illustrates the risks associated with interconnected systems that are used aboard modern commercial vessels. 
As a result of the integration of information technology with propulsion, navigation, and engineering systems on board, it may be difficult for a successful intrusion to affect the vessel's physical performance. Neither incident has disrupted operational operations, caused harm to crews, or damaged the environment, and no attribution of these attacks has been made public to Iran. 
Additionally, the investigation takes place in the context of increased suspicions of Iranian-linked cyber activity by US agencies.
A maritime security expert has warned that it may be difficult to determine the actual extent of attacks against shipping, especially when vessel operators restore systems quickly without thoroughly investigating how an intrusion occurred. 
According to Lloyd's List, US agencies are monitoring cyber threats involving almost 20 ships worldwide, which raises concerns over the growing vulnerability of commercial shipping. The risks extend beyond individual ships as well.
Navigating, propulsion, steering, and other critical operations of commercial vessels are increasingly dependent on connected digital systems. The compromise of these systems could negatively impact a vessel’s movements or create broader difficulties around major shipping routes and ports. 
A serious disruption could result in a fire, explosion, or spill. An investigation of the tanker is also underway as key maritime routes are becoming increasingly congested.
It is important to note that the crossing of the Strait of Hormuz has been repeatedly disrupted and attacked during the conflict, while Iran-backed Houthi forces have exerted increased pressure on vessels operating around the Red Sea and Bab al-Mandab Strait. 
Since cyberattacks could take place against vessels traveling outside these traditional conflict zones, maritime security concerns have been intensified. US authorities have not yet established that Iran was responsible for the attacks.
There has also been no determination as to whether the attacks were connected to each other. Further investigations by the FBI and Coast Guard may clarify whether the attacks were isolated incidents or part of a broader campaign targeted at maritime infrastructure.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: