HomeIncidentsVL Prosperity Cyberattack in Gibraltar: 30-Hour Blackout Remains Unverified

VL Prosperity Cyberattack in Gibraltar: 30-Hour Blackout Remains Unverified

Save
Saved

AIS data confirms the VLCC’s voyage from Egypt to the United States, but claims of engine-room system manipulation have not received independent or official confirmation

Brinztech Reported Interference With Tanker Systems

The Liberian-flagged tanker VL Prosperity was allegedly subjected to a cyberattack while passing through the Strait of Gibraltar, according to a report cited by the Ukrainian transport publication CTS.

A Brinztech alert states that the incident occurred on August 7, 2026, as the vessel was carrying crude oil from Egypt’s Sidi Kerir terminal to the United States.

Brinztech claims the attack caused a complete 30-hour disruption of satellite and radio communications. The attackers allegedly penetrated the vessel’s internal network and gained access to parts of its engine-room operational technology.

According to the report, unauthorized actors increased the main engine’s speed while reducing cooling-fluid flow. Fuel and lubricating-oil tank monitoring was also allegedly disabled, potentially preventing the crew from receiving warnings about leaks, pressure anomalies or abnormal temperatures.

No engine damage, fire, oil spill or injuries have been reported.

The Claim Appeared Before the Brinztech Alert

The publicly available source chain does not indicate that Brinztech participated directly in the incident investigation.

Its article is dated August 21. One day earlier, Iran’s Mehr News Agency published substantially the same allegations, citing an unnamed crew member. Mehr did not provide a technical report, documentation from the shipowner or confirmation from maritime authorities.

Brinztech similarly did not identify its source, disclose the intrusion method, name any malware or publish indicators of compromise. The company also states at the end of its alert that it does not warrant the validity of external claims.

As of August 28, the incident had not been confirmed by the vessel operator, the Liberian flag administration, its classification society, its insurer, UK Maritime Trade Operations or the maritime authorities of Spain and Gibraltar. Maritime intelligence outlet Seavanta has also classified the story as a single-source claim without official maritime confirmation.

The Vessel and Its Voyage Are Confirmed

The tanker’s existence and its voyage from Egypt to the United States are supported by public vessel data.

VL Prosperity carries IMO number 9683697. According to VesselFinder, the Liberian-flagged crude oil tanker was built in 2015 and is classified as a Very Large Crude Carrier. It is 333 metres long, 60 metres wide and has a deadweight capacity of 319,547 tonnes.

The vessel departed Sidi Kerir on August 1 with Galveston listed as its destination. Public AIS services recorded it in the Galveston area on August 24, indicating that it completed the transatlantic voyage after the alleged incident.

The reported figure of 2.3 million barrels is broadly consistent with the maximum carrying capacity of a VLCC of this size. AIS data cannot confirm the actual cargo quantity or its ownership, however. That would require a cargo manifest or confirmation from the shipper.

No Aramco Ownership Has Been Established

Saudi captain Mamdouh bin Jaber Al-Saket subsequently commented on the alleged incident, describing it as an attack against the vessel’s “nervous system.” Several reports identify him as an employee of Saudi Aramco.

The published material does not establish that Al-Saket was aboard VL Prosperity, participated in the incident response or received information from the vessel’s owner. His comments therefore cannot be treated as technical or corporate confirmation.

Public registries also do not identify VL Prosperity as an Aramco-owned tanker. The Lloyd’s List directory names GMF GLV No. 4 SA as the registered owner, while vessel databases identify South Korea’s HMM Ocean Service as the ISM manager.

The tanker may have been carrying Saudi Aramco crude or operating under a charter arrangement, but no relevant contract has been disclosed. Vessel ownership, technical management, chartering and cargo ownership are separate commercial relationships.

Engine Manipulation Would Require OT Access

The reported scenario is technically possible but would represent a sophisticated cyber-physical attack.

Changing engine speed and cooling-fluid flow would require access beyond the vessel’s email or administrative network. The attackers would need to reach operational technology such as programmable controllers, engineering workstations, control panels or the engine-room automation system.

Such access could result from inadequate network segmentation, compromised remote maintenance, stolen credentials, infected equipment or a vulnerability in supplier software. Without details of VL Prosperity’s onboard configuration, the actual intrusion path cannot be determined.

Manipulation of propulsion parameters should leave records in controller and alarm-system logs. Protective systems would also normally be expected to alert the crew, restrict operation or shut down equipment if overheating or abnormal pressure reached critical levels.

Confirmation would require controller logs, satellite-provider records, network captures, evidence of altered control logic and a forensic report from specialists who inspected the vessel after arrival.

None of this evidence has been published.

A Communications Outage Does Not Prove an Attack

A 30-hour loss of communications would not by itself demonstrate that the vessel was hacked. Possible alternative causes include satellite-terminal failure, a power problem, configuration errors, radio interference or the crew shutting down individual systems.

AIS and shipboard satellite communications use different infrastructure. A gap in a public AIS track does not necessarily mean that a vessel lost all communications, because reception depends on terrestrial and satellite coverage.

Conversely, a continuous AIS track would not exclude a failure affecting other communications equipment. The allegation therefore cannot be verified from public vessel movements alone.

Confirmation Would Change the Maritime Risk Assessment

If engine-room interference is eventually confirmed, the case would become one of the most serious known cyberattacks against the operational systems of a commercial vessel.

Loss of propulsion or control in the Strait of Gibraltar could cause a collision or require emergency towing in one of the world’s busiest shipping corridors. On a laden crude carrier, the consequences could also include fire and marine pollution.

The International Maritime Organization requires cyber risks to be addressed through shipping companies’ safety-management systems. IACS requirements also cover protection, attack detection, response and recovery for both information technology and onboard operational technology.

Operators need to separate administrative and machinery networks, restrict remote access, monitor supplier accounts, maintain independent backup communications and regularly test the crew’s ability to control critical equipment manually.

The Incident Should Remain Classified as Unverified

The identity and specifications of VL Prosperity, its departure from Sidi Kerir and its subsequent arrival in the Galveston area are supported by public data.

The 30-hour communications blackout, penetration of engine-room systems, manipulation of propulsion parameters and disabling of tank monitoring remain allegations unsupported by an openly available technical investigation.

Until the shipowner, operator, flag state or maritime authorities issue a statement, the event should be described as a reported or alleged cyberattack rather than an established maritime casualty.

Read also: Cyber Warfare in the Shadow of the Hormuz Crisis: A New Threat to Global Shipping

LEAVE A REPLY

Please enter your comment!
Please enter your name here

>> RELATED NEWS

>> Related news

>> Category

Popular
Comment
Like
- Advertisment -
Google search engine

Reviews (0)

This article doesn't have any reviews yet.