VL Prosperity: What MTSA Cybersecurity Already Requires

Table of Contents

On August 21, 2026, U.S. Coast Guard (USCG) law enforcement, USCG Cyber Protection Team (CPT), a vessel inspector and FBI Cyber Action Team (CAT) boarded a 333-meter crude oil tanker in the Atlantic. The ship, later identified through Iranian and open-source reporting as the VL Prosperity, was three weeks out from Egypt’s Sidi Kerir terminal, headed for Galveston with roughly 2.3 million barrels of crude. Its network showed signs of compromise by a foreign cyber actor. Investigators spent four days aboard, working with the crew and the operator to hunt and assess the vessel’s systems before it reached a U.S. port.

A second 227-meter liquefied petroleum gas tanker, The Kohaku, was boarded three days later in the Gulf of Mexico, on August 24, after a suspected, related attack. Two tankers, days apart, both Texas-bound as they had earlier transited the Strait of Gibraltar. Both vessels transited a chokepoint that’s seeing heavier traffic because Hormuz access has been disrupted by the Iran War. Separate reporting also alleged that Vivt Africa LNG experienced cyber-related disruption affecting navigation, communications, and cargo-operation systems on 9 September 2026. Dragos has not independently corroborated the reported compromise or identified technical evidence supporting the alleged OT impacts.

What’s confirmed so far is limited: USCG and FBI found malicious cyber activity and performed incident response, noting no physical damage, environment impacts or crew injuries at the time. Unconfirmed claims, that the attacker reached propulsion, navigation, and cargo systems directly, come only from Iranian state media. Ships and ports have an attack surface that’s absorbed versions of this exposure for years. The Maritime Transportation Security Act (MTSA) has been around since 2002, with cyber only recently being accounted for as an addition to the regulation effective July 2025. The regulatory timing is not a coincidence and echoes the importance of asset owner and operator readiness against high-consequence cyber incidents impacting extended operational technology (xOT).

That pattern isn’t specific to this incident; roughly 90% of global trade moves by ship, which alone makes maritime transportation a prime target. Commercial vessels carry a real attack surface, with engines that move a 333-tanker controlled by computers dependent on electronic charting and GPS to know where they are.

  • 2017 - a ransomware attack on Maersk cost the shipping firm between $250-$300 million. NotPeya wasn’t built for shipping specifically, and it didn’t need to be; it just needed a foothold in a company that happens to run and operate vessels. NotPetya moved through Maersk’s IT systems in 2017 and still stopped operations across container terminals worldwide, because those systems scheduled and tracked every physical move a terminal made.
  • 2021 - a suspected state-sponsored entity linked group compromised a web server at the Port of Houston Authority by exploiting a vulnerability in a password-management and single-sign-on platform. Port Houston had a facility security plan in place under MTSA, and no operational data or systems were impacted as a result.
  • 2022 - Blackcat ransomware disrupted Oiltanking and Mabanaft IT networks for several days, where automated tank loading processes had no manual fallback, forcing Royal Dutch Shell to reroute oil deliveries to other depots.
  • 2023 - DNV’s 2023 ransomware incident is a quieter version of the same exposure: it reached fleet management software running across thousands of vessels, administrative on paper, but load-bearing for the crews who depend on it to move cargo safely. That same year, the Port of Nagoya lost several days of cargo movement due to Lockbit 3.0 ransomware.
  • 2024 - a USB-borne RAT campaign moved through ships in Greece, Norway, and the Netherlands and reportedly reached machinery-monitoring and navigation systems directly, the same category of system now in question on the VL Prosperity.
  • 2025 - the MSC Antonia ran aground after GPS spoofing fed its navigation system false position data. GPS interference in the Red Sea spiked in early 2025, with more than 180 vessels affected in the first three months of the year alone.

In June 2022, an explosion at the Freeport LNG facility in Texas triggered months of speculation about the cause. Federal investigators ultimately traced deficiencies in valve testing procedures and alarm thresholds, not a cyberattack. The consequence side of an OT failure; valves, alarms and temperature monitoring look the same whether the root cause is a misconfigured procedure or manipulated system. The categories of systems named in the Iranian claims about VL Prosperity were engine cooling, fuel and lube-oil systems, which are the same category of system that failed at Freeport LNG in 2022. It lines up with how Dragos defines the xOT environment: not by what a system is, but by what happens to physical operations if it fails.

A breakdown of the attack surface of ship itself, there are three distinct zones each with their own risk profile:

  • Bridge Systems: integrated navigation, GPS, ECDIS, dynamic positioning, AIS, GMDSS, radar, voyage data recorders, bridge navigational watch alarm systems and shipboard security alarm systems
  • Cargo management: the cargo control room and its equipment, loading computers, remote cargo tracking and sensing, level indication, valve remote control, ballast water systems, reefer monitoring and water ingress alarms
  • Propulsion, machinery management and power control: engine governor, power management, integrated control system, alarm system, bilge water control, water treatment, emissions monitoring, HVAC monitoring, damage control and fire alarm monitoring

The claims, again while unconfirmed, about VL Prosperity land inside the propulsion and machinery management zone specifically, which carries the highest safety consequence, not just the highest business-disruption cost.

The common thread, on ships and in ports, is the same one Dragos has been pointing at for years: the system that matters isn’t defined by whether it looks technical or administrative, onboard or onshore. It’s defined by what happens to a physical process if it fails.

MTSA cyber-incident reporting to the National Response Center has been mandatory since the rule took effect on July 16, 2025. As of January 12, 2026, every MTSA-regulated facility and vessel had to put personnel with access to IT or OT systems through cybersecurity training, with key personnel retrained annually. By July 16, 2027, owners and operators needed a designated Cybersecurity Officer (CySO), a completed Cybersecurity Assessment, and an approved Cybersecurity Plan on file with the Coast Guard. The Coast Guard has also said it will step up Port State Control scrutiny of cybersecurity practices on foreign flagged vessels, which is the category the VL Prosperity falls into.

Both of those deadlines apply to MTSA-regulated U.S.-flagged vessels and facilities, not to a foreign-flagged vessel like VL Prosperity. VL Prosperity falls instead under two other parts of the same rule: the Coast Guard’s stepped-up Port State Control scrutiny of cybersecurity practices on foreign-flagged vessels, and a separate provision that now treats a cyber incident as a reportable “hazardous condition” under 33 CFR 160.202, which foreign vessels must report through their Notice of Arrival and immediate notification to the nearest Captain of the Port. The rule was already partway into force when this happened. Regulators weren’t caught off guard by the timing. Most of the industry still has real work left to do before the 2027 deadline closes that gap.

Dragos works through regulations like MTSA with a crawl, walk, run framework rather than trying to solve everything at once. Crawl is about establishing awareness and foundational understanding: knowing what you have and what the regulation is asking before you start making decisions. Walk is where you begin structured implementation, turning that awareness into documented processes, architectural decisions, and assigned accountability. Run is where the program matures: controls are tested under real conditions, gaps are actively closed, and compliance becomes operational discipline rather than a project with a deadline. Applied to MTSA:

  • Crawl: Establish awareness by getting your asset inventory right first. MTSA codifies this at 33 CFR 101.650(b)(3): an accurate inventory of network-connected systems with critical IT and OT systems designated as such, including software versions, firmware revisions, and configurations. It’s the foundation the rest of the regulation sits on, and it extends past your own fleet: if a Cybersecurity Officer marks a vendor-managed system as critical, that vendor relationship is now inside the compliance boundary too.
  • Walk: Start segmenting before the 2027 deadline forces the issue. Network segmentation underpins nearly every other MTSA requirement, and it’s usually where the gap between how a network was designed and how it operates today is widest. Building the real, intentional boundary between IT and OT networks takes longer than a single firewall between satellite internet and propulsion, and it’s not something to start in month 23 of a 24-month clock.
  • Run:
    • Know what the CySO role requires before you assign it. It’s not a rebadged CISO. The qualifications include understanding maritime operations and cybersecurity and is ultimately designated by the owner or operator of the U.S.-flagged-vessel, facility, or Outer Continental Shelf facility.
    • As part of the 2027 deadline to have a Cybersecurity Assessment, owners and operators must analyze all networks to identify vulnerabilities to critical IT and OT systems, along with the associated risk on each asset. In particular, the CySO is tasked with ensuring identification and mitigation of all Known Exploitable Vulnerabilities (KEVs) in critical IT or OT systems, documenting resolved and unresolved vulnerabilities noting any the owner/operator knowingly accepted as risk. Attackers rarely need a purpose-built OT exploit when a known, unmitigated weakness in a connected IT system serves as an access vector, getting them onto the same network as everything else.

Maritime is catching up to a problem the rest of critical infrastructure has already been fighting for years, and the fight is winnable when the basics are in place first. That’s the same work Dragos does across power, water, oil and gas, and manufacturing: seeing what’s on the network, understanding what an attacker could do with it, and keeping operations running.

Sources

Liz Martin joined Dragos as a Solutions Architect from the National Security Agency (NSA), where she held previous roles as a Network Warfare Cyber Planner and Computer Network Defense Analyst. Liz is well-versed in leading major incident response efforts as well as network assessments across the U.S. Government and Intelligence Community supporting the defense of National Security Systems. She holds a master’s degree in cybersecurity technology and bachelor’s degree in cybersecurity management and policy. Liz was previously a competitive female bodybuilder and personal trainer.