HomeMalware & ThreatsCoast Guard Boardings of Hacked Vessels – New Details

Coast Guard Boardings of Hacked Vessels – New Details

Published on

spot_img

US-Bound Supertankers Breached by Cyberattacks: Official Insights

In a concerning development for maritime security, known vulnerabilities were exploited during two cyberattacks on U.S.-bound supertankers in August, resulting in the intervention of Coast Guard and FBI cyber specialists. A federal official disclosed this revelation this week, stating that both incidents involved unpatched weaknesses in the ships’ on-board systems, highlighting the ongoing cyber risks faced by critical maritime infrastructure.

The incidents, which led to the vessels being boarded, were first reported by CBS News and other media outlets last month. However, the acknowledgment of the exploitations linked to unpatched vulnerabilities had not previously surfaced. According to the official, who requested anonymity, one of the central messages was clear: “This was preventable. Both incidents were the result of known vulnerabilities.”

On September 16, a joint statement from the FBI and the Coast Guard clarified that security boardings of the two supertankers took place on August 21 and August 24 in the Gulf of Mexico. This operation aimed to verify the integrity of the operational and information technology systems aboard the vessels, following evidence suggesting that their networks had been compromised. Fortunately, the statement assured that there were no reports of disruptions in operations, safety risks to crews, or environmental hazards, allowing the vessels to continue their journey to U.S. ports.

The heightened scrutiny surrounding these boardings was attributed to suspicions of Iranian involvement, although no official confirmation or attribution to specific actors was provided at the time. These incidents underscore the vulnerability of maritime operations to cyber threats.

With the recent establishment of new rules by the Coast Guard, cybersecurity standards have been set for U.S.-flagged vessels. Moreover, the updated regulations now mandate that both foreign and U.S. vessels report any cyber incidents to U.S. authorities prior to their entry into port. The implications of these regulations are significant: vessels found to be in violation may face boarding by Coast Guard officials and federal agencies, including Customs and Border Protection and the FBI.

Retired Rear Adm. John Mauger, who held prominent roles within the Coast Guard’s cyber and enforcement divisions before retiring in 2024, remarked on the rarity of such Captain of the Port orders. According to Mauger, it is uncommon to have more than a few vessels facing such orders in any given week, particularly for cyber-related issues. Historically, these orders have typically addressed traditional maritime concerns such as navigational disruptions or health risks among the crew.

However, the emergence of cyber specialists as part of a boarding team marks a significant shift in the Coast Guard’s approach. This change is a testament to the agency’s commitment to adapting to modern threats in cyberspace while collaborating with vessel owners to address hacking risks. Adm. Amy Grady, who leads the Coast Guard Cyber Command, disclosed to CBS that the Cyber Protection Teams that boarded the vessels detected “malicious cyber activity” within the on-board systems, and while further details were withheld, the statement underscored the importance of these interventions.

The reporting of cyber incidents remains anonymous, a protocol the Coast Guard emphasizes to foster trust with vessel operators. As noted by the anonymous official, the concern surrounding reputational damage is particularly acute among legitimate companies, many of which are publicly traded.

The mystery deepened as other sources, including a blog post by Dragos’ Global Senior Director of Threat Hunting, Liz Martin, identified the two vessels involved as the Liberian-flagged crude oil supertanker VL Prosperity and the Marshall Islands-flagged liquefied petroleum gas supertanker Kohaku. Furthermore, Martin noted that a third vessel, the liquefied natural gas supertanker Vivit Africa LNG, also underwent a cyberattack while en route to Italy.

All three cyber incidents appeared to transpire as the ships navigated the Straits of Gibraltar, provoking exploration into a potentially larger pattern of cyber threats against maritime operations. Martin, drawing from her experience as a former NSA network warfare cyber planner, stated, “If I put my analyst hat on, I would venture to say there could be a theme there.” However, she acknowledged that critical pieces of the puzzle remain elusive.

The convergence of operational technology (OT) and information technology (IT) has blurred lines, with modern maritime operations intricately connected to shore-side IT systems. This connectivity means that an IT breach has the potential to open the door to OT systems, allowing intruders to manipulate massive vessels that transport up to two million barrels of oil. Consequently, the fallout from these cyber activities could endanger crew safety and disrupt normal operations, foreshadowing possible catastrophic scenarios.

Mandatory reporting requirements that were introduced last year have begun to provide visibility into the maritime sector’s cyber activities. Martin elaborated, emphasizing the myriad incidents occurring in the maritime domain, many of which might go unnoticed or unreported. She proposed that if vessel owners actively searched for cybersecurity threats, the revelations about the scale of the issue might be shocking.

Recent data from Honeywell Technologies unveiled that a significant portion of maritime operators faced considerable cybersecurity challenges. In a survey, 87% of participants from the maritime sector reported experiencing a significant OT cybersecurity incident within the past year, outstripping the average across all sectors. The survey also underscored the maritime sector’s comparatively low maturity in cybersecurity practices, indicating that many organizations lack essential operational readiness and detailed asset inventories.

As a former leader in Coast Guard Cyber Command, John Felker highlighted that the maritime sector presents a "target-rich environment" for cybercriminals, characterized by minimal protective measures. The increasing frequency of cyberattacks within this traditionally vulnerable sector raises pressing concerns about maritime safety and security in an age where cyber threats pose significant risks to global trade and national security.

Source link

Latest articles

Google’s Suspension of Bug Bounty Program Underscores Increasing Challenges in AI Vulnerability Triage

In the dynamic landscape of cybersecurity, experts are emphasizing the need for a critical...

Nikkei Reports Two Compromised Employee Cloud Accounts

Unauthorized Access at Nikkei: Phishing Incident and Data Compromise In a troubling incident for the...

Tenant Isolation Emerges as a Key Buying Criterion with FusionAuth’s New UK Office Opening

FusionAuth Establishes European Sales Team Amid Growing Demand for Data Control In a significant move...

Denmark Prepares for Surge in Phishing Attacks

Denmark Faces Major Data Breach, Affecting Nearly 9 Million Residents In a significant breach of...

More like this

Google’s Suspension of Bug Bounty Program Underscores Increasing Challenges in AI Vulnerability Triage

In the dynamic landscape of cybersecurity, experts are emphasizing the need for a critical...

Nikkei Reports Two Compromised Employee Cloud Accounts

Unauthorized Access at Nikkei: Phishing Incident and Data Compromise In a troubling incident for the...

Tenant Isolation Emerges as a Key Buying Criterion with FusionAuth’s New UK Office Opening

FusionAuth Establishes European Sales Team Amid Growing Demand for Data Control In a significant move...