HMM Ocean Service Co., Ltd.
Incident posture
Linked entities
- Victim
- HMM Ocean Service Co., Ltd.
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Coast Guard personnel and FBI agents boarded a Texas‑bound oil tanker after determining its network may have been compromised by a foreign actor; Iranian state media reported that hackers had taken control of propulsion, navigation and cargo systems and caused a 30‑hour loss of communications. The vessel, identified as the VL Prosperity, is managed by HMM Ocean Service Co., Ltd. A combined team of Coast Guard law enforcement, vessel inspectors, cyber protection specialists and FBI cyber action teams examined the ship’s operational and information technology systems, worked with the crew and the company’s operators to eradicate the threat, and later reported no operational disruptions, vessel instability, danger to crew or environmental impact. The United States has not attributed the incident to any specific actor, while Iranian outlets amplified the story as evidence of a new cyber front in the U.S.–Iran conflict.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 7, 2026, the VL Prosperity, a Liberian‑flagged very large crude carrier managed by South Korea‑based HMM Ocean Service Co., Ltd., lost communications while sailing from Egypt’s Sidi Kerir terminal toward Galveston, Texas. Iranian state media outlet Mehr News Agency reported on August 20 that the vessel had been attacked and that hackers had penetrated its engine‑room systems, reduced engine cooling flow, increased engine speed, and interfered with fuel and lubricating‑oil systems, resulting in a loss of communications for approximately thirty hours. The Coast Guard later stated that it had determined the ship’s network may have been compromised by a foreign actor and, on August 21, boarded the vessel in the Atlantic with a team comprising law enforcement personnel, a vessel inspector, Coast Guard Cyber Protection Team members, and FBI Cyber Action Team operators. HMM Ocean Service confirmed that the Coast Guard had boarded the VL Prosperity after the ship passed through the Strait of Gibraltar, where unconfirmed reports of the incident first surfaced publicly.
The boarding team examined both the vessel’s operational technology and information‑technology systems, working with the crew and the ship’s corporate operators to eradicate the alleged threat. Iranian reports claimed that the attackers had obtained control over propulsion, navigation, and cargo systems, though the Coast Guard has not disclosed the extent of any breach and has not attributed the activity to a specific actor. On September 15, 2026, the Coast Guard announced that there were currently no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts stemming from the incident. HMM Ocean Service stated that it maintains rigorous cyber protocols to ensure the safety and security of the vessels under its care. The article also notes that modern tankers use interconnected operational technology to control propulsion, navigation, and cargo systems, and that a hostile state reaching those systems could theoretically manipulate the vessel’s movement or critical machinery, potentially turning the tanker into a weapon against a port.
Following Mehr’s initial report, Iranian state media amplified the story, with Tasnim News Agency publishing a headline four days later that read “No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?” The U.S. government has not provided further details on the possible breach beyond confirming indications of network compromise, and no official attribution has been made. The incident remains under investigation by the Coast Guard and FBI, with the vessel having resumed its voyage toward Texas after the boarding and remediation efforts.
Sources
Sources available to members: 1 source.