OTSecurity

USCG, FBI assess OT and IT systems aboard two oil tankers following suspected foreign cyberattacks


The U.S. Coast Guard and FBI are investigating suspected cyberattacks on two oil tankers bound for the U.S., with authorities boarding the vessels last month after indications that their networks may have been compromised by foreign cyber hackers, according to CBS News and ABC News. On Aug. 21, a specialized team of Coast Guard law enforcement personnel, a vessel inspector, Coast Guard cyber protection members and FBI cyber operators boarded one foreign-flagged commercial tanker in the Gulf of Mexico to assess its OT (operational technology) and IT systems.

The USCG-FBI investigation comes after one of the vessels reportedly lost communications for more than 30 hours while transiting the Strait of Gibraltar, while a second tanker was boarded by U.S. officials on Aug. 24 for a similar assessment, ABC News reported. Authorities have not publicly attributed the suspected attacks to a specific actor, although sources told ABC News investigators were examining whether Iran or another actor seeking to exploit the conflict between Iran and the United States could have been involved. 

The Coast Guard and FBI said there were no reports of operational disruptions, vessel instability, physical danger to crews or environmental impacts. 

This disclosure comes as American utility company CenterPoint Energy said it became aware in September of an online post by a third party claiming to have obtained a dataset containing certain customer information, prompting the company to activate its cybersecurity incident response protocols and launch an investigation with third-party cybersecurity experts.

“The Company’s delivery of electric and gas services has not been impacted and remains operational and undisrupted,” CenterPoint detailed in an SEC filing this week. “As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company’s financial condition or results of operations.”

It added, “While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems (the “Incident”). The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law. The Company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue.”

The filing also mentioned that CenterPoint “has incurred, and expects to continue to incur, certain expenses related to the Incident and its response to the Incident. The Company maintains customary cybersecurity insurance coverage and believes this insurance will offset related costs.”

Commenting on the USCG-FBI action, John Strand, owner at Black Hills Information Security, wrote in an emailed statement that there’s a lot of conversation right now about attacks against OT, especially water and power systems, given the current geopolitical climate. “But tankers are absolutely on the menu as well. What makes these environments so attractive is that much of this technology doesn’t have the same endpoint security you would expect on a Windows 11 workstation. You often don’t have EDR running on these systems. That creates a rich target for attackers because many of the defensive technologies we’ve come to rely on in traditional IT simply aren’t there.”

“It appears two separate claims are circulating, and they’re being treated as one,” Dahvid Schloss, OSCP, chief operating officer at Suzu Labs, wrote in an emailed statement. “The first one is from the Coast Guard, which has acknowledged indications that the vessel’s network was compromised, with no reported operational disruptions. The other comes from Iranian media, citing a single unnamed crew member, which has alleged a much more extensive compromise involving cooling, fuel systems, and other critical elements of the vessel. Those claims have not been independently verified as of yet, so it’s important to keep your skeptical hat on.” 

Additionally, Schloss said that it’s important to note that Iranian media reporting on the incident also does not establish Iranian responsibility; attribution remains unresolved. “Regardless, this is a significant situation. A suspected compromise aboard a tanker warrants serious attention even if propulsion and other critical systems continued operating normally. The fact that the Coast Guard and FBI deployed their cyber teams to assess the vessel and remove potential threats shows the importance, even if it does not validate the more dramatic claims.”

“The reported communications outage raises a separate technical question,” according to Schloss. “A compromise of the communications suite, or plain RF interference, could explain a 30-hour outage without a threat actor ever touching the ship’s controls. GPS receivers and satellite terminals are chronically soft targets. The Strait of Gibraltar in particular is a well-documented GNSS interference corridor, so that’s a possibility I’d want investigators to rule in or out early, but an outage on its own still tells you nothing about how far an intrusion actually reached.”

“I think if we take anything away from this ordeal, it is that nothing came of this compromise. No major disruption, environmental impact, or danger to the crew, and if a threat actor genuinely had control of propulsion on a fully loaded crude carrier, the obvious question is why nothing was done with it,” Schloss assessed. “When I’ve seen this pattern in the past, it usually points to a proof-of-concept or recon attack, more colloquially put, a rehearsal, not a performance. Now, a rehearsal for what? Can’t say, and neither can anyone else right now, but that’s for the investigators to work out. Either way, with global oil supply already at its tightest it’s been in modern history, this isn’t a low-consequence practice run.”

Damon Small, board of directors at Xcape Inc., wrote in an emailed statement that physical maritime operations and global energy supply chains face severe operational risks when shipboard networks are compromised. 

“Contrary to official statements downplaying the event, a 30-hour communications blackout on a crude carrier is a significant operational disruption. Vessels underway depend heavily on continuous communications for navigation and collision avoidance, meaning an unannounced blackout can easily precipitate a maritime disaster,” Small evaluated. “Modern commercial watercraft rely on multi-channel connectivity including Very Small Aperture Terminal (VSAT), cellular, and Wi-Fi systems, making a sustained blackout indicative of critical bridge system failure.” 

He added that defenders must strictly segment bridge communication links from physical OT domains, audit firmware across satellite hardware, and monitor for anomalous signal degradation.



Source link