Τελευταία Νέα
Διεθνή

Iran cyberattack hits US tankers off Gibraltar, Trump weighs response

Iran cyberattack hits US tankers off Gibraltar, Trump weighs response
A few lines of malicious code can potentially transfer the geopolitical confrontation between the US and Iran thousands of kilometers away from the field of conventional conflict

An extremely unusual cybersecurity case in international shipping has raised an alarm in the US, with American authorities investigating two potential cyberattacks against energy vessels heading toward ports in Texas. Within the framework of the investigation, the possibility of Iranian involvement is also being examined, without, however, any technical or other piece of evidence having been publicly presented so far that attributes the attacks to Tehran.
According to the Wall Street Journal, American officials are investigating whether Iran or another foreign actor is behind the incidents. No organization or state has claimed responsibility, and American authorities have not announced an official attribution of the attack.
The first vessel that found itself at the center of attention is the VL Prosperity, a massive tanker approximately 333 meters long flying the flag of Liberia. The ship had departed from the Egyptian terminal of Sidi Kerir bound for Galveston in Texas, transporting more than two million barrels of crude oil.
The affair presents particular interest because the first detailed reports regarding the incident did not originate from American authorities, but from Iranian media outlets.

Trump: I made a big decision, veto by Russia and China on sanctions against Iran

In the wake of this development, President of the United States Donald Trump stated that Washington is approaching a critical turning point in the war with Iran, leaving open the possibility of resuming large-scale military operations.
In an interview with Axios, Donald Trump mentioned that he will soon have to decide whether the US will return to extensive strikes aimed at bringing the conflict to a definitive conclusion.
«I have a big decision ahead of me. Do I want to go in and take them out or not? It is a big decision», he stated characteristically, without, however, announcing that a final decision has been reached or that new military orders have been issued.
At the same time, Russia and China exercised a veto in the UN Security Council, blocking an American draft resolution that provided for the extension of the mandate of the Panel of Experts monitoring the implementation of sanctions against Iran for another year.
The draft, which had been submitted by Washington, garnered 11 votes in favor.
Russia and China voted against, using the veto power they possess as permanent members of the Security Council, while Pakistan and Somalia abstained.

02_186.jpg

Cyberattack in Gibraltar

On August 20, the Mehr news agency reported that the VL Prosperity had come under a cyberattack on August 7 while transiting the Strait of Gibraltar. Citing a member of the crew, the Iranian news agency argued that the intruders had gained access to engine room systems, affecting, among other things, engine cooling, engine revolutions, and systems related to fuel and lubricants. A loss of communications for approximately 30 hours was also reported.
These specific technical details have not been confirmed in their entirety by the US.
This is crucial for assessing the affair. The timely coverage of the incident by Iranian media does not in itself constitute proof that Iran was connected to the attack. On the contrary, the initial report noted that neither side had claimed responsibility.

111_26.png

Coast Guard and FBI boarded the vessel

On August 21, when the VL Prosperity had approached the US, a specialized team from the US Coast Guard along with personnel from the FBI boarded the tanker.
The mission included cybersecurity experts, law enforcement officers, and vessel inspectors. Both conventional information technology systems (the so-called IT) and operational technology systems (the networks that can connect directly to the actual mechanical functions of a ship) were inspected.
American officials confirmed that there were indications of network intrusion by foreign cyber actors and that operations were carried out to identify and remove the threat.
However, the official outcome so far is far more limited than certain reports suggest.
The Coast Guard announced that there were no reports of operational disruption, vessel instability, physical risk to the crew, or environmental impacts. It has also not publicly confirmed that the hackers took control of propulsion, navigation, or cargo operations.

01_202.jpg

A second vessel under the microscope

The case became even more serious when it was revealed that this was not an isolated incident.
The second vessel, which according to the Wall Street Journal was the Kohaku, had likewise moved through Gibraltar heading toward Texas. American agencies identified indications that its own network had also been breached.
On August 24, a second boarding operation was conducted by the Coast Guard and the FBI. In this case as well, investigators examined the digital environment of the ship, searching for potential similarities with the attack on the VL Prosperity.
The core question is now whether the two incidents form part of the same operation.
To answer this, specialists are examining the method of entry into the networks, the malicious software that was potentially used, the behavior of the intruders, and other digital footprints. Subsequently, they compare these techniques with known methods of cyber groups.
Precisely here lies the difficulty of any hasty accusation against Iran.
In cyberspace, the technical attribution of an attack to a specific state can require weeks or months. Attackers can utilize intermediary servers, stolen infrastructure, or the tools of other groups to mask their real identity.
So far, the American government has not announced that it possesses sufficient evidence to name Iran.

03_106.jpg

Why the case worries Washington so much

Beyond who is behind the attacks, the incidents reveal a deeper problem for the US and international shipping.
Modern commercial ships rely on an increasing number of interconnected electronic systems for navigation, communications, engines, cargo management, and safety operations.
The US Coast Guard itself has warned that the growing convergence between IT and operational technology creates new attack surfaces and that a severe breach could, theoretically, cause physical consequences to a ship.
In late August, Washington even established a new maritime cybersecurity office, formally acknowledging that the digitalization of shipping has created new risks for critical infrastructure and the economy.
In this environment, the incidents involving the VL Prosperity and the Kohaku take on broader geopolitical significance.

112_32.jpg

The Iranian dimension and unanswered questions

Suspicion of Iranian involvement inevitably falls within the wider confrontation between Washington and Tehran. Yet geopolitical suspicion is one thing, and technical proof is another.
The Wall Street Journal notes that Iran constitutes one of the directions of the American investigation. It does not state that the investigation has concluded, nor that a definitive attribution of responsibility has been made.
Indeed, the fact that Iranian media published information about the attack prior to the official disclosure of the American operations has raised questions, but it may have more than one explanation.

04_62.jpg

Special operations on the vessels

Mehr cited a crew member, while the management company of the VL Prosperity later confirmed that American authorities had indeed boarded the vessel.
Consequently, the most significant element of the case to date is perhaps precisely what is missing: a proven identity of the perpetrator.
The two cyberattacks appear to have been serious enough for the Coast Guard and the FBI to conduct special operations on board the ships. This is confirmed.
That Iran was behind them, however, is not.
And until the investigation presents technical data, turning a potential Iranian involvement into a certainty would precede the findings of the American authorities themselves.
The real message of these incidents is broader: in the new era of maritime rivalry, a tanker no longer needs to be hit by a missile or a mine to face a grave threat. A few lines of malicious code can potentially transport geopolitical confrontation thousands of kilometers away from the field of a conventional conflict.
And that is a problem concerning not only Iran and the US, but global shipping as a whole.

 

www.bankingnews.gr

Ρoή Ειδήσεων

Σχόλια αναγνωστών

Δείτε επίσης