- Coast Guard and FBI board energy tankers after cyberattacks during transit
- Holidaymakers flee to sea as fire engulfs Gava Waterman Milna Resort in Croatia
- Rachida Dati’s trial opens in Paris over €900,000 Renault-Nissan payments
- EU Moves to Designate Canada as Its First Associate Member
- CPP Investments and Brookfield launch $50 billion Maple Fund for national projects
- Barack Obama announces death of family dog Sunny at age 13
- Passengers panic as cabin ceiling collapses during emergency landing in Iran
- Doctors warn of challenges faced by aid workers targeted by Israel
Hunt for Tube hero who gave blind man his shoes after he lost one through the gap The hunt is on find an ‘absolute hero’
Get you up to speed: Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?
U.S. Coast Guard personnel and FBI agents boarded the VL Prosperity, a Liberian-flagged crude oil tanker, in response to cyberattacks that compromised the vessel’s systems while it was near the Strait of Gibraltar. Investigators found evidence of malicious cyber activity but did not determine the ship’s safety for navigation.
The Coast Guard’s Cyber Protection Team has undertaken 40 to 50 similar missions in the past year, indicating an increase in cyber threat response operations. Investigators are examining malware and IT systems aboard the VL Prosperity and plan to provide the vessel owner with recommendations to address identified vulnerabilities.
U.S. Coast Guard Cyber Command is advising vessel owners to implement essential cybersecurity measures following recent cyberattacks on energy tankers, with Rear Adm. Amy Grable stating, “We need everybody to pay attention to this.” Investigations into the attacks are ongoing, as authorities explore potential connections to Iran or other foreign adversaries.
What remains unclear — U.S. officials have not publicly identified the specific foreign adversary believed to be behind the cyberattacks on the VL Prosperity and the other tankers.
Coast Guard and FBI board energy tankers after cyberattacks during transit
U.S. Coast Guard personnel and FBI agents boarded two Texas-bound energy tankers last month after cyberattacks struck the vessels while they were traveling toward the United States, according to U.S. officials.
One of the vessels was the VL Prosperity, a 1,093-foot Liberian-flagged crude oil tanker headed to Galveston, Texas. Iranian state media identified the ship shortly after the incident and claimed hackers had gained access to its propulsion, navigation and cargo systems, knocking out communications for 30 hours.
The Coast Guard has not publicly pinned the attacks on Iran. But Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, told WTX US News in a network exclusive interview that investigators did find evidence of a malicious cyber actor.
“They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity,” Grable said.
The U.S. is investigating whether the two cyberattacks are connected and whether Iran or another foreign adversary was behind the attacks.
What happened?
The VL Prosperity is what’s known as a supertanker — more than three football fields long and capable of carrying roughly 2.3 million barrels of oil.
Public vessel data shows the ship departed Egypt’s Sidi Kerir oil terminal on Aug. 1 headed for Galveston. U.S. officials say it slowed near the Strait of Gibraltar around the time of the cyberattack before continuing across the Atlantic and toward the U.S.
Iran’s Mehr News Agency reported on Aug. 20 that the VL Prosperity had been attacked on Aug. 7 while transiting through the Strait of Gibraltar. Citing an unnamed crew member, Mehr alleged hackers breached the engine room, reducing engine cooling flow, increasing engine speed and interfering with fuel systems.
Rob Lee, CEO of Dragos, an industrial cybersecurity firm specializing in operational technology, said the Iranian report’s details were technically plausible, but warned that authorities have not yet revealed who was behind the incident.
“The details that they published, from what we understand of these types of vehicles and ships and similar, is spot on,” Lee said. “Everything they’re saying is very realistic.”
The next day, Aug. 21, Coast Guard cyber personnel, law enforcement officers, a vessel inspector and FBI Cyber Action Team operators boarded the ship for four days.
Grable said Coast Guard teams had been alerted by interagency partners and went offshore with the FBI to climb aboard — one of roughly 40 to 50 missions the Coast Guard’s Cyber Protection Team has undergone in the past year.
She said investigators were hunting for malware and combing through information technology systems to root out malicious activity.
“The real thing we’re concerned about is those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel,” Grable added.
Typically, investigators collect data that is later analyzed, and Grable told WTX US News that the Coast Guard plans to provide the vessel owner with recommendations for patching vulnerabilities. She stressed that response teams did not find any evidence indicating the ship had become unsafe to navigate when they boarded it.
How difficult is it to attack a ship?
The concern surrounding large cargo vessels and maritime critical infrastructure transcends stolen files or disrupted communications.
More and more, modern commercial vessels run on internet-connected systems, relying on them for navigation, propulsion, steering, ballast and additional critical machinery. A cyberattack that penetrates those operational systems could potentially be weaponized or manipulated.
“When these vessels are highly connected, they’re susceptible to cyber threats,” Grable said, warning that an attack could lead to “a vessel blocking a waterway or a pollution incident or any other number of safety and security hazards to our ports and waterways.”
The danger that a large vessel could be compromised near an American port is something that authorities fear.
“Of course we’re worried about a collision, an explosion, anything that blocks the channel for other vessels to safely enter and exit the port, pollution incidents — we’re kind of worried about the whole gamut,” Grable said.
The potential economic impact is also colossal. Grable said $5.4 trillion in commerce flows through U.S. ports annually — which could mean high economic stakes for even a relatively small disruption.
“Any small delay, because of a cyber breach, like, for example, if a port has to shift to manual operations, it causes a big delay with tankers and cargo vessels coming in and out of the port,” she said.
Perhaps most concerning, Grable said the technical barrier may not be as high as the public assumes.
How sophisticated would an attacker have to be to move beyond breaking into a computer network to manipulating machinery aboard a modern tanker?
“Not necessarily that sophisticated,” Grable told WTX US News. “There is malicious source code that people can get their hands on.”
Grable said that code is available right now, and added that “artificial intelligence is accelerating the rate at which we need to take action.”
She urged operators to zero in on network segmentation, phishing attacks and basic cyber hygiene. “Just taking basic precautions would prevent most of these occurrences.”
Just one firewall away
On many ships, the barrier between a satellite internet connection and critical onboard systems can be as fragile as a single firewall.
Behind that firewall, Lee said, can be a shared network containing “navigation, propulsion, ballast, steering, ship command — everything on one shared network.”
Lee explained that artificial intelligence could make that problem worse because it can assist attackers in picking out weakly protected systems, speeding up attempts to breach internet-facing systems on energy carriers.
“The very thing that we think is our one protection — not that you should have one protection — is the very thing that AI is actually really good at,” Lee said.
Still, experts concede that while older vessels may not have the same digitally connected control systems, even on modern ships, reaching critical machinery still requires some knowledge of the onboard environment.
Is ‘remote hijacking’ a real threat?
Asked whether cyber access to a ship could amount to a form of remote hijacking, Grable called it a fair description of the broader risk.
“That’s a good way to characterize it, and yes, it is a concern,” she said.
Lee agreed that the scenario is realistic if an attacker gains a foothold.
“I do think there’s a realistic concern,” Lee said, describing the possibility of remotely messing with a maritime asset, even running it aground.
But former Coast Guard cyber official Quinton DuBose seemed skeptical of the notion that hackers could simply take over an entire supertanker like a remote-controlled vehicle.
“I’d be kind of cautious about saying that somebody can just take control of the ship,” DuBose said. “Ships are incredibly complicated systems.”
The more realistic threat, he said, may be an attacker disrupting one or more critical subsystems enough to make the vessel unsafe.
“Rather than looking at it as, ‘okay, I’m going to take full control of this thing,’ it’s, ‘what systems can I disrupt to the point where it affects the safe handling and makes the ship less safe to operate,'” DuBose said.
Iranian state media claims under scrutiny
The U.S. has not publicly stated who is behind either cyberattack. But Iranian state media began pushing out content around the VL Prosperity incident before U.S. authorities even publicly acknowledged the boarding.
Four days after Mehr’s initial report, Iran’s Tasnim News Agency published an article with the headline, “No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes?”
DuBose stressed that the Iranian narrative remains unverified, cautioning that Iranian-linked actors are often quick to oversell their cyber influence.
Attribution in cyberspace can take weeks or months, DuBose added.
According to Grable, investigators typically compare the attacker’s tactics, techniques and procedures — effectively their digital fingerprints — against known threat actors.
“We look at things called TTPs, which are tactics, techniques and protocols that certain adversaries use — kind of like their trademark fingerprints on how they gain access to systems and what they do and what their payloads are,” she said.
A warning to the maritime industry
For Coast Guard Cyber Command, the growing concern is that increasingly connected vessels create more porous entry points for attackers, as ships adopt satellite communications and connect IT networks with their onboard control systems.
“Because they’re facing the internet, that is a vector for attackers to gain access and deploy malicious activity on the vessels,” she said.
DuBose said the industry should take the threat seriously, while resisting the notion that all vessels are suddenly vulnerable to remote takeover.
He added that maritime infrastructure is so critical that the federal government “has increasingly imposed baseline cyber requirements across the sector.”
Grable’s warning to vessel owners and operators was blunt: “We need everybody to pay attention to this.”
‘Cheer up, you caught the bad guy,’ says killer Virginia McCullough as she is arrested for murdering her parents
A woman who murdered her parents “in cold blood” before hiding them in makeshift tombs for four years told officers to “cheer up, you caught the bad guy” as she was arrested in her home.
Virginia McCullough, 36, poisoned her father John McCullough, 70, with prescription medication and fatally stabbed her mother Lois McCullough, 71, shortly afterwards in 2019.
She ran up large debts on credit cards in her parents’ names and after their deaths, she continued to spend their pensions until she was finally caught in 2023.
In body-worn video footage released by police, a handcuffed – and eerily calm – McCullough told officers: “I did know that this would kind of come eventually.
“It’s proper that I serve my punishment.”
She said she had slipped something into her father’s drink then put his body under a bed on the ground floor, and put her mother’s body in an upstairs wardrobe.
McCullough, having been arrested on suspicion of double murder, told an officer: “Cheer up, at least you’ve caught the bad guy.”
She added: “I know I don’t seem 100% evil.”
At the police station, she told officers where a kitchen knife was, which she described as a “murder weapon”, and a hammer which she said “will still have blood on it”.
McCullough, of Pump Hill, Chelmsford, Essex, was sentenced to life imprisonment on Friday with a minimum term of 36 years at Chelmsford Crown Court, after she admitted to their murders between 17 and 20 June 2019 at an earlier hearing at the same court.
Chelmsford Crown Court heard how she hid their bodies in makeshift tombs at the family home in Great Baddow in Essex, then told persistent lies to cover her tracks.
The court heard she cancelled family arrangements and frequently told doctors and relatives her parents were unwell, on holiday or away on lengthy trips.
But concerns over Mr and Mrs McCullough’s welfare were raised in September 2023 by a GP at their registered practice, and Essex County Council’s safeguarding team referred these to police.
The GP had not seen the couple for some time and said Mr McCullough had failed to collect medication and attend scheduled appointments. It was found McCullough had frequently cancelled appointments, using a range of excuses to explain her father’s absence.
Police said a missing persons investigation was initially launched and McCullough lied to officers, claiming her parents were travelling and would be returning in October.
It became a murder investigation, and when officers forced entry to the house in Pump Hill on September 15 2023, McCullough confessed that her parents’ bodies were in the house and that she had killed them.
Nicola Rice, a specialist prosecutor for the Crown Prosecution Service, said: “McCullough callously and viciously killed both of her parents before concealing their bodies in makeshift tombs within their home address.
“She spent the next four years manipulating and lying to family members, medical staff, financial institutions, and the police, spending her parents’ money and accruing large debts in their name.”
She added: “This was a truly disturbing case, which has left behind it a trail of devastation, and I can only hope that the sentence passed today will help those who loved and cared for Lois and John begin to heal.”
G20 waters down support for Ukraine amid pressure for peace talks
FT.com Tweet
The Tech Titan Who Led His Company From a 68-Square-Foot Jail Cell
WSJ Business Tweet
Defense alliance NATO chief Mark Rutte has met US President-elect Donald Trump to discuss global security issues, according to a NATO spokesperson.
The meeting took place in Palm Beach, Florida.
During his first term as US president, 2017-2020, Trump pushed for European NATO countries to spend more on defense and described the alliance’s cost-sharing as unfair to the US.
Rutte took over as NATO chief from Norwegian Jens Stoltenberg in November.
Before taking office in January, Trump has nominated Pete Hegseth for the post of defense secretary, which has raised eyebrows among many allies.
Hegseth, 44, has served as an infantry captain in Iraq and Afghanistan, but has no senior military or government officer experience.
Multiple missiles were fired in an airstrike towards a densely populated part of Lebanon’s capital early on Saturday.
The huge airstrike targeted Beirut’s Basta neighbourhood, and no prior warnings were given by the Israeli military. The largely residential area was struck last month.
At least one violent explosion was heard across the city, Reuters witnesses said, and plumes of smoke could be seen. Scenes of massive destruction at the site were shared online, including a massive crater in the ground.
“Beirut, the capital, woke up to a horrific massacre, as the Israeli enemy’s air force completely destroyed an eight-story residential building with five missiles on Al-Mamoun Street in Basta,” the state-run National News Agency reported.
The health ministry put the initial death toll at four, with 23 wounded. The number is expected to climb in the coming hours as search and rescue efforts continue.
It came after a long day of Israeli airstrikes on Beirut’s southern suburbs, which have been non-stop since last week.
The cross-border fighting between Israel and the Iran-backed Hezbollah militant group escalated into a full-blown war in mid-September.
Israel has bombed southern Lebanon, Beirut’s southern suburbs and the eastern Beqaa region, and has sent ground troops across the border. Hezbollah has continued to fire rockets deeper into Israel.
What to Watch
Amazon prime - TV & Netflix
What to Watch
Love Sports
- Good News
- Readers Digest
Subscribe to Updates
Get the latest creative news from FooBar about art, design and business.

