U.S. Coast Guard and FBI personnel boarded two commercial vessels traveling toward the United States through the Gulf of Mexico last month after signs that hackers had entered the ships’ computer networks. The agencies disclosed the operation on Thursday.
The boardings occurred on Aug. 21 and Aug. 24 aboard two vessels sailing under foreign flags.
The operation came as U.S. authorities confronted a series of cyber incidents that media reports have linked to Iran since conflict erupted between Washington and Tehran.
According to the FBI, a joint team involving the bureau and the Coast Guard boarded the vessels after receiving “indications that the networks of both vessels were compromised.”
The bureau’s statement covered both ships and both boarding dates.
The Coast Guard provided a narrower account, referring only to the boarding conducted on Aug. 21.
It said “foreign cyber actors” were involved in the incident, but the service did not identify the actors or provide additional information about them.
Neither the FBI nor the Coast Guard offered further details about what personnel discovered during the boardings.
The agencies also did not explain why the FBI described two operations while the Coast Guard discussed only one.

The U.S. Cybersecurity and Infrastructure Security Agency did not provide a separate account of the incidents.
Instead, the agency referred questions about the matter back to the Coast Guard.
Corey Ranslem, CEO of the maritime security group Dryad Global, said his firm confirmed the identity of one vessel as VL Prosperity. The ship sails under the Liberian flag, according to the information provided.
VL Prosperity is currently anchored in waters near Galveston, Texas, according to vessel tracking data from LSEG and MarineTraffic.
Liberia’s flag registry did not immediately answer a request for comment concerning the vessel.
Iran’s Mehr news agency had reported on Aug. 20 that VL Prosperity suffered what the outlet called “a major cyberattack.”

According to that report, the vessel was passing through the Strait of Gibraltar when the alleged intrusion occurred.
Mehr reported that the ship’s communications were knocked out for 30 hours.
The Iranian news agency based additional details about the alleged incident on the account of an unnamed crew member.
According to Mehr, hackers also entered systems in the vessel’s engine room.
The report alleged that the intruders reduced the engine’s cooling flow, increased its speed, and disabled the ship’s fuel tank and engine oil tank.
The Iranian news agency did not identify who was suspected of conducting the alleged attack.
That left the reported incident without a publicly named perpetrator even as the Coast Guard separately pointed to the involvement of foreign cyber actors.

Ranslem said a cyberattack focused on a ship is not especially difficult to execute, despite the dramatic effects such an intrusion can produce.
His assessment reflected the vulnerability involved when attackers gain access to critical networks aboard a commercial vessel.
“We are expecting these types of attacks to continue and will expand in the very near future,” Ranslem said.
His warning followed the two Gulf of Mexico boardings and the separate Iranian report describing the alleged disruption aboard VL Prosperity.
For now, the agencies’ public descriptions remain limited to indications that both vessel networks were compromised and the Coast Guard’s statement about foreign involvement.
The identities of the cyber actors, the name of the second ship, and further operational details were not provided.
