Executive Summary
In August 2024, the U.S. Coast Guard and FBI conducted joint offshore security boardings of two foreign commercial tankers in the Gulf of Mexico following cyberattacks that compromised their networks. The first vessel, carrying oil and natural gas, was hacked while transiting the Strait of Gibraltar and lost communications for over 30 hours. Authorities investigated potential Iranian involvement or threat actors exploiting U.S.-Iran tensions, as part of broader concerns about 'dark fleets' carrying sanctioned oil using digital masking techniques.
This incident highlights the growing convergence of cybersecurity threats with critical infrastructure and supply chain security, particularly as nation-state actors increasingly target maritime operations to disrupt global commerce and energy transportation networks.
Why This Matters Now
Maritime cyberattacks are escalating as geopolitical tensions rise, with threat actors targeting vessels carrying critical energy resources to disrupt global supply chains and exploit sanctions evasion networks.
Attack Path Analysis
Nation-state attackers likely exploited unencrypted maritime communication systems to gain initial access to vessel networks, then leveraged compromised operational technology systems to establish persistence and control. The attackers maintained command and control through satellite communications while potentially exfiltrating sensitive cargo manifest and navigation data. The 30+ hour communication blackout in the Strait of Gibraltar suggests deliberate disruption of critical maritime systems, likely targeting sanctioned oil transport operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited vulnerable maritime communication systems and unencrypted vessel networks, potentially targeting VSAT satellite communications or port-based network connections during transit through the Strait of Gibraltar
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Application Layer Protocol
Disable or Modify Tools
Network Sniffing
Endpoint Denial of Service
Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Network Segmentation and Micro-segmentation
Control ID: Networks.Advanced.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – Incident Reporting
Control ID: Article 11
NYDFS 23 NYCRR 500 – Incident Response Plan
Control ID: 500.16
PCI DSS 4.0 – Network Security Testing
Control ID: 11.4
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Maritime
Direct nation-state attacks on vessel networks require enhanced encrypted traffic monitoring, east-west segmentation, and egress security for operational technology systems.
Oil/Energy/Solar/Greentech
Tanker cyberattacks targeting Iranian/Russian sanctions evasion expose critical infrastructure to lateral movement risks requiring zero trust segmentation and anomaly detection.
Transportation
Supply chain disruption from maritime cyber incidents demands multicloud visibility, threat detection capabilities, and secure hybrid connectivity for logistics coordination.
Government Administration
Coast Guard and FBI joint response operations highlight need for encrypted communications, policy enforcement, and kubernetes security for interagency coordination platforms.
Sources
- Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattackshttps://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/Verified
- Executive Order on Strengthening United States Leadership in Clean Energy and Climate Resilience Jobshttps://www.whitehouse.gov/briefing-room/presidential-actions/2024/01/27/executive-order-on-strengthening-united-states-leadership-in-clean-energy-and-climate-resilience-jobs/Verified
- Maritime Cybersecurity Frameworkhttps://www.cisa.gov/sites/default/files/publications/Maritime%20Cybersecurity%20Framework_Final.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have reduced the scope and impact of this maritime cyberattack by constraining lateral movement between vessel systems and limiting attacker reachability across operational technology networks.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely have constrained initial access scope by requiring identity verification and limiting network reachability to segmented maritime system zones rather than allowing broad network access
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely have limited privilege escalation by constraining access between network segments and reducing the attacker's ability to move from communication systems to operational technology networks
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained lateral movement by enforcing inspection and policy validation for inter-system communication, reducing attacker reachability across vessel operational networks and navigation equipment
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained command and control traffic patterns through satellite communications, potentially limiting the duration and scope of the communication blackout
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained data exfiltration by limiting outbound data transfer paths and enforcing policy controls on sensitive cargo manifest and navigation data transmission
While CNSF would likely have reduced the blast radius and scope of impact, some operational disruption to vessel communications could still occur within segmented network zones
Impact at a Glance
Affected Business Functions
- Maritime Navigation Systems
- Cargo Operations
- Communication Systems
- Supply Chain Logistics
Estimated downtime: 2 days
Estimated loss: N/A
Potential compromise of vessel operational technology systems, navigation data, and communication networks. Maritime tracking and cargo manifest information may have been accessed during the 30+ hour communication blackout period.
Recommended Actions
Key Takeaways & Next Steps
- • Implement encrypted traffic controls (HPE) for all maritime satellite communications and vessel-to-shore data transmissions to prevent interception and manipulation of critical navigation and cargo data
- • Deploy zero trust segmentation between operational technology (OT) and information technology (IT) systems on vessels to limit lateral movement from initial network compromise to critical vessel control systems
- • Establish multicloud visibility and control capabilities for maritime operators to monitor anomalous interactions between vessel systems and shore-based infrastructure in real-time
- • Implement egress security and policy enforcement to prevent unauthorized data exfiltration of sensitive cargo manifests, navigation routes, and operational data from compromised vessel networks
- • Deploy threat detection and anomaly response capabilities specifically designed for maritime environments to baseline normal vessel communications patterns and detect covert command and control channels



