Recent Cyber Incidents Underscore the Need for Maritime Cybersecurity Compliance
Highlights
- Federal authorities recently responded to a potential cyberattack on a commercial oil tanker bound for the U.S. and a liquefied natural gas carrier, highlighting vulnerabilities within the Maritime Transportation System (MTS).
- The incidents coincide with pending congressional legislation – the MTS Cybersecurity Budget and Evaluation Report (MTS CYBER) Act of 2026 (H.R. 7625) – and an evolving regulatory framework that could strengthen U.S. Coast Guard cybersecurity oversight of the marine sector.
- Maritime industry stakeholders should evaluate their cyber risk management practices in anticipation of heightened regulatory scrutiny.
In mid-August 2026, a very large crude carrier (VLCC) traveling from the Mediterranean Sea toward the U.S. Gulf Coast reportedly experienced a significant network intrusion. According to the U.S. Coast Guard, the vessel's systems may have been compromised by a foreign threat actor. Iranian state media separately claimed that attackers obtained access to the vessel's propulsion, navigation and cargo management systems, resulting in a communications blackout lasting approximately 30 hours.
The Liberian-flagged supertanker – capable of transporting more than 2 million barrels of crude oil – was en route to Texas when authorities intervened. Unconfirmed reports first emerged as the ship transited the Strait of Gibraltar, with foreign media attributing the attack to hostile actors who allegedly manipulated engine-room systems, including cooling flow, engine speed and fuel controls.
Federal Response to the Oil Tanker Incident
The Coast Guard assembled a multiagency response team that boarded the vessel in the Atlantic Ocean on August 21, 2026. The team included Coast Guard law enforcement officers, marine inspectors, Cyber Protection Team members and FBI Cyber Action Team operators. The group examined both the vessel's operational technology (OT) and information technology (IT) systems and worked with the crew and corporate management to remediate the intrusion. Coast Guard officials confirmed there were no reports of operational disruptions, vessel instability, crew endangerment or environmental impacts.
LNG Carrier Incident
According to reports, a Liberia-flagged liquefied natural gas (LNG) carrier – owned by a South Korean shipping company and operating under charter to a major commodities trader – had loaded cargo at an LNG export facility in Louisiana. As the vessel approached the Adriatic Sea, crew members reportedly lost access to certain internal control systems. The ship remained idle off the coast of Italy before abandoning its scheduled call at an LNG terminal near Rovigo and reversing course toward Spain.
According to unverified crew accounts, threat actors may have targeted the vessel's control systems prior to berthing. Crew members alleged that attackers temporarily accessed steam pressure and safety valve systems during the Strait of Gibraltar transit, and later compromised tank pressure control systems and the boil-off gas management cycle – which, if accurate, could have elevated the risk of tank rupture.
Government Agency Response to the LNG Incident
Italian coast guard authorities characterized the event more cautiously, stating the master reported a malfunction in systems monitoring cargo parameters requiring company technician intervention. The cause could not be definitively determined.
This LNG incident reflects a broader pattern of concern. Reports indicate U.S. authorities are monitoring close to 20 vessels globally for potential cyber-related threats.
Cybersecurity Risks to Maritime Operations
These incidents illustrate why cyber threats to maritime operations extend beyond data theft or communications disruption. Modern commercial vessels increasingly rely on interconnected operational technology to manage critical functions – propulsion, navigation, ballast and cargo handling systems are often networked and internet-accessible. A successful intrusion could allow a malicious actor to manipulate a vessel's course, disable safety equipment or interfere with machinery. In a worst-case scenario, threat actors could cause groundings, collisions or environmental disasters or even weaponize a vessel against port infrastructure.
These incidents underscore federal actions taken over the past two years to address cybersecurity vulnerabilities in the Marine Transportation System (MTS). In February 2024, the White House announced coordinated measures targeting maritime cyber threats, reflecting concerns about ransomware attacks, unauthorized access to control systems, supply chain espionage and theft of proprietary data.
In April 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the U.S. Department of War, U.S. Department of Energy and several other agencies, released joint guidance for helping organizations safeguard OT systems from emerging cyber threats by transitioning to Zero Trust architecture.
The U.S. is not alone in ramping up efforts to address maritime cyber threats. In April 2025, the International Maritime Organization (IMO) updated its Guidelines on Maritime Cyber Risk Management, which provide high-level recommendations and functional strategies to safeguard shipping from current and emerging cyber threats that can be incorporated into existing risk management processes. The Coast Guard has recognized the IMO guidelines as complementary to its cybersecurity regulations and baseline requirements.
On September 22, 2026, Honeywell Technologies released its 2026 OT Cybersecurity Benchmark Report, which assessed more than 600 cybersecurity, risk, compliance and operations leaders across critical infrastructure sectors, including maritime, manufacturing, energy, oil and gas, and healthcare. Nearly nine in 10 maritime respondents suffered a significant operational technology cyber incident during the past year, underscoring the timeliness of increased regulatory interest in improving maritime cybersecurity.
Regulatory Landscape: The MTS CYBER Act
These incidents arrive at a pivotal moment for U.S. maritime cybersecurity policy. On September 15, 2026, the House Committee on Transportation and Infrastructure favorably reported the Maritime Transportation System Cybersecurity Budget and Evaluation Report (MTS CYBER) Act of 2026 (H.R. 7625). The legislation directs the Comptroller General to evaluate the Coast Guard's budget and capabilities as a Sector Risk Management Agency (SRMA) for the marine transportation system, focusing on adequate funding for cybersecurity personnel, training and compliance oversight. The bill designates the U.S. Department of Transportation and U.S. Department of Homeland Security as co-SRMAs.
The bill's primary sponsor emphasized the Coast Guard's critical role in protecting port terminals and vessels from cybersecurity threats, noting the agency requires additional resources for sector risk management. Committee leadership expressed bipartisan agreement that cyber operations pose an increasing threat to the MTS.
The Evolving U.S. Maritime Cybersecurity Framework
The Biden Administration committed more than $20 billion over five years to U.S. port infrastructure, including rebuilding domestic manufacturing capability for ship-to-shore cranes. This investment responded to concerns about Chinese-manufactured port cranes – particularly those from a state-owned enterprise supplying nearly 80 percent of cranes at U.S. ports. The Coast Guard issued Maritime Security Directive 105-4, imposing cybersecurity requirements on owners and operators of these cranes.
President Joe Biden signed Executive Order 14116, amending regulations under Title 33 of the Code of Federal Regulations to address maritime cyber threats. The order expanded Coast Guard authority to establish security zones, control vessel movements presenting cyber threats, inspect cyber systems and require correction of unsatisfactory conditions. The order mandated immediate reporting of cyber incidents to the FBI, CISA and Coast Guard captain of the port.
Building on these efforts, the Coast Guard issued a final rule on maritime cybersecurity, published in the Federal Register on January 17, 2025 (90 FR 6298). The rule, which took effect on July 16, 2025, applies to U.S.-flagged vessels, Outer Continental Shelf (OCS) facilities and facilities regulated under the Maritime Transportation Security Act of 2002 (MTSA). This rulemaking followed prior expansions of Captain of the Port authority that formally recognized cyber vulnerabilities as threats to port security and safety. (See Holland & Knight's Law360 article, "What 4 Cyber Protection Actions Mean for Marine Transport," June 17, 2024.) The corresponding regulations now appear in 33 C.F.R. Part 101, Subpart F.
In August 2026, the Coast Guard took a further step to institutionalize its cybersecurity capabilities by establishing the Office of Maritime Cybersecurity Policy (CG-MCP) under the Director of Inspections and Compliance (CG-5PC). Announced in ALCOAST 266/26, the new office serves as the Coast Guard's central contact for developing and implementing policies governing cyber safety and security of the MTS. The office's establishment follows the recent publication of first-of-its-kind regulations governing cybersecurity in the MTS and directly supports Executive Order 14269, "Restoring America's Maritime Dominance." This organizational change signals the Coast Guard's sustained commitment to addressing IT and OT cybersecurity risks in maritime critical infrastructure.
Takeaways for the Maritime Industry
These incidents – combined with legislative momentum behind the MTS CYBER Act and evolving regulatory framework – signal that maritime cybersecurity will remain a priority for federal regulators and the U.S. Congress. Vessel owners, operators, port facilities and terminal operators should consider the following steps:
Assess Cyber Risk Management Programs. Organizations should review their existing cybersecurity policies and procedures to ensure they adequately address OT and IT vulnerabilities, including risks associated with networked propulsion, navigation and cargo systems.
Monitor Regulatory Developments. The MTS CYBER Act's progress through Congress, along with Coast Guard rulemaking activity, will shape compliance obligations. Industry stakeholders should track these developments and engage with regulators as appropriate.
Prepare for Increased Enforcement. As federal agencies expand their cyber capabilities and receive additional resources, maritime companies should anticipate heightened compliance oversight and potential enforcement actions for cybersecurity deficiencies.
Develop Incident Response Protocols. The coordinated federal response to the tanker incidents demonstrates the importance of having robust incident response plans that facilitate cooperation with the Coast Guard, FBI and other authorities.
Consider Legal Risk. Maritime stakeholders should recognize that cyber incident reporting obligations create potential legal liabilities. Determining reportability can present challenges, and some internal investigation with counsel is advisable. Effective incident response planning should account for coordination with legal counsel, as adverse publicity and litigation frequently follow data breaches. Investigations and reporting should be structured to preserve privilege and minimize litigation exposure.
Holland & Knight's experienced maritime and cybersecurity counsel can assist with maritime cybersecurity compliance, regulatory strategy and incident response planning. Contact the authors with any questions.
Information contained in this alert is for the general education and knowledge of our readers. It is not designed to be, and should not be used as, the sole source of information when analyzing and resolving a legal problem, and it should not be substituted for legal advice, which relies on a specific factual analysis. Moreover, the laws of each jurisdiction are different and are constantly changing. This information is not intended to create, and receipt of it does not constitute, an attorney-client relationship. If you have specific questions regarding a particular fact situation, we urge you to consult the authors of this publication, your Holland & Knight representative or other competent legal counsel.