The physical risk is not yet the same as the confirmed cyber risk. Verified: U.S. officials said Coast Guard and FBI teams boarded two foreign-flagged, U.S.-bound tankers after indications their networks had been compromised; the Coast Guard confirmed malicious cyber activity on the VL Prosperity. The report says unpatched vulnerabilities were exploited, but the public evidence does not identify the vulnerable product, CVE, affected network zone, or exploit telemetry. Investigators found no evidence that the vessel was unsafe to navigate, and authorities reported no operational disruption, instability, crew danger, or environmental impact. Unverified: claims involving engine cooling, engine speed, and fuel systems originated in Iranian reporting. There is no comparable public evidence of manipulated propulsion, steering, ballast, cargo handling, navigation, or safety controls—and no public attribution to Iran.
Architecturally, I would provisionally place the demonstrated compromise around shipboard IT, communications, or remote-access functions—the maritime equivalent of Purdue Level 3/3.5. Reaching bridge or machinery automation would mean Levels 2/1, but that crossing has not been demonstrated. Full tanker takeover is therefore hypothetical. The credible safety scenario is narrower: enough degraded communications, navigation information, machinery monitoring, or control redundancy that the master can no longer establish safe operation.
Immediate action should be controlled rather than dramatic: preserve logs and volatile evidence; suspend nonessential vendor access; rotate exposed credentials; and isolate the affected IT or satellite-communications segment only after the master, chief engineer, and equipment vendors confirm that doing so will not interrupt bridge, engine-room, alarm, or distress communications. Independently validate steering, propulsion and cooling, fuel control, ballast, cargo alarms, navigation displays, position sources, and backup communications using approved procedures. Do not push patches or reconfigure segmentation underway unless the change has been tested and rollback is available. Continue the voyage only if essential functions, redundancy, and trusted communications remain stable; otherwise hold in safe water, delay port entry, or arrange pilots, tug support, and a controlled anchorage as conditions permit.
For a U.S.-bound tanker, confirmed malicious access plus uncertain separation from operational networks is already enough, in my assessment, for pre-arrival Coast Guard/Captain of the Port notification. Port-state or enhanced safety intervention becomes justified by any authenticated access to bridge or machinery networks, malicious configuration or command evidence, unexplained setpoint changes, loss of redundancy, disagreement between independent sensors, impaired propulsion/steering/navigation/communications, or inability to demonstrate containment. Emergency safety escalation should not wait for attribution if operators observe a time-correlated physical anomaly or cannot prove that essential systems remain independently controllable.