Day Lila

Cybersecurity · Thursday, 17 September 2026

01 Briefing what happened

Two tankers heading for the US showed signs of being hacked. The Coast Guard and FBI boarded both at sea.

Cybersecurity 12 sources

The US Coast Guard and the FBI said on Wednesday that they boarded two foreign ships in the Gulf of Mexico in August, after signs that both ships' networks had been broken into. Nobody has said who did it.

30+ hours

that one tanker could not communicate after it was hacked near Gibraltar

according to news reports gathered by CyberScoop, a US security news site [2]

2 ships

boarded at sea by the Coast Guard and FBI, on 21 and 24 August

both were heading for US ports in the Gulf of Mexico [2]

23 days

between the second boarding and the agencies' public statement

the statement came on 16 September, after newspapers had reported the attacks [2]

The lead story — what happened

  • The US Coast Guard and the FBI said on Wednesday that they boarded two foreign commercial ships heading for the US last month. [2]
  • The boardings took place in the Gulf of Mexico on 21 and 24 August, after signs that the computer networks of both ships had been broken into. [2]
  • The two agencies say there are no reports of the ships being disrupted, of danger to the crews, or of harm to the environment. [2]
  • News reports say both ships were tankers carrying oil and natural gas. [2]
  • The first was hacked in the Strait of Gibraltar, the narrow sea between Spain and Morocco, and lost communication for more than 30 hours. [2]
  • Bloomberg News named one of the tankers as VL Prosperity, which flies the flag of Liberia and was sailing from Egypt to the US. [1]
  • Mehr, a news agency backed by Iran's government, quoted a crew member who said the attackers raised the engine speed and switched off the fuel and engine-oil tank. [1] No official has confirmed this.
  • Each boarding team mixed Coast Guard police, a Coast Guard cyber-defence team, a ship inspector and an FBI team that investigates computer attacks. [1][2]
  • The Coast Guard did not answer questions about how the attack worked or who was behind it, and no hacking group has claimed it. [1]
  • Investigators are reported to be asking whether Iran, or another group using the war between Iran and the US as cover, was responsible. [2]
  • Coast Guard cyber teams already inspect 'dark fleet' tankers, which carry oil from Iran and Russia that is under sanctions and use digital tricks to hide their movements. [2]
  • An order signed by President Joe Biden in 2024 gave the Coast Guard more power to respond when a ship or port is attacked through its computers. [2]
  • Ports have been hit many times before. North Carolina's ports had to switch to working by hand after an attack in early August, and the Port of Seattle refused a ransom in 2024. [1]

Who is involved

  • The US Coast Guard

    the US force that polices ships and ports; it led both boardings and gave few details

  • The FBI's Cyber Action Team

    the US federal police unit that investigates serious computer attacks; it joined both boardings

  • VL Prosperity

    a tanker under the flag of Liberia, named by Bloomberg as one of the hacked ships; it is now off the coast of Texas

  • Mehr

    a news agency backed by Iran's government; it published a crew member's account that the engine was tampered with

How it unfolded

  1. 7 Aug VL Prosperity is attacked in the Strait of Gibraltar, according to Mehr [1]
  2. 21 Aug Coast Guard and FBI teams board the first ship in the Gulf of Mexico [2]
  3. 24 Aug a second ship is boarded [2]
  4. 15 Sep Bloomberg reports that the Coast Guard boarded a tanker in a cyberattack investigation [2]
  5. 16 Sep the Coast Guard and FBI confirm the boardings in a joint statement [2]

Where this points

Watch whether the Coast Guard names an attacker or says what the hackers could control on board. That would show whether this was spying or an attempt to interfere with a ship. [1][2]

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

Attacks on ships and sea cables Building

Two tankers heading for the US showed signs in August that their networks had been broken into. [2] This spring Britain, Norway and the US caught Russian submarines near Svalbard, Norway's Arctic islands, practising with a weapon built to disable undersea internet cables. [3]

Police taking away attack tools Building

The US Justice Department seized NightmareStresser, a website that rented out attacks to knock other websites offline. [4] Police in Ukraine charged three men with selling 610,000 stolen Roblox game accounts. [5] The US House voted to let local police spend federal money on scam investigations. [6]

Software flaws under attack High

Attackers have used a flaw in Citrix's NetScaler gateway since 3 September, two weeks after a fix was released. [7] Acronis, a backup software company, said a flaw in one of its tools was already being used when it released the repair. [8][9]

What an attack costs afterwards Steady

The insurer Hiscox found that a company hit by an attack was down for 32.8 hours on average. [11] The International Meteor Organization, a club of sky watchers, expects weeks of partial downtime after its website was attacked. [10]

The rest of the day

9 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    A website that rented out attacks is seized

    The US Justice Department seized NightmareStresser on Tuesday, working with officials in Canada. [4] The site sold floods of fake internet traffic that knock a website or game server offline, at prices from 25 to 19,999 euros. [4] Court papers say it was used in hundreds of attacks since 2022 on schools, government agencies and gaming platforms. [4] The department had already seized another of its web addresses in 2022, and it would not say whether anyone was arrested this time. [4]

    Why it matters — Security experts said the site had more than 550,000 users, so one seizure removes a tool that a very large number of people could hire. [4] The US says it has charged 12 people over sites like this in eight years. [4]

  2. 03

    Three Ukrainians charged over 610,000 Roblox accounts

    Prosecutors in Lviv, a region of western Ukraine, said on Tuesday that three men will stand trial for stealing access to more than 610,000 Roblox accounts. [5] Roblox is an online game platform used mostly by children and teenagers. [5] The group stole the small files that keep a player logged in, so they could enter accounts without passwords. [5] Software then checked which accounts held game money or rare items, and the best were sold one by one. [5]

    Why it matters — Some accounts sold for about 80 US cents each, and prosecutors think the scheme could have made about $480,000. [5] All three men are in custody and face up to 12 years in prison. [5]

  3. 04

    US House votes to fund local scam police

    The US House of Representatives passed the GUARD Act on Tuesday, a bill backed by members of both main parties. [6] It lets local police use existing federal grant money to investigate financial scams, hire experts and buy tools that trace stolen cryptocurrency. [6] Victims often say their cases are too small for federal agents, while their local police do not have the tools to follow the money. [6] The bill still has to pass the US Senate before it can become law.

    Why it matters — Americans lost a record $11.4 billion in cryptocurrency scams in 2025, $8.6 billion of it in fake investments, often run from abroad. [6] AARP, a large US group for older people, praised the bill, saying scam victims had told it their local police lacked the tools to investigate. [6]

  4. 05

    Allies caught Russia practising to cut Arctic cables

    Britain, Norway and the US tracked and confronted Russian submarines near Svalbard this spring, two Western officials told Reuters. [3] The officials said the vessels were practising a new weapon built to disable undersea internet cables without leaving traces. [3] Two cables 1,400km long link Svalbard to mainland Norway, and they carry data from the world's largest satellite ground station. [3] The Russian ships left without damaging any cable, and Russia denies carrying out sabotage. [3]

    Why it matters — Undersea cables are critical to the internet and to money transfers between countries. [3] Britain and Norway also took their evidence to Russia's government, hoping that showing what they had seen would make it hesitate. [3]

  5. 06

    US tells agencies to fix NetScaler in three days

    CISA, the US government's cyber-defence agency, added a flaw in Citrix's NetScaler gateway to its list of holes that attackers are already using. [7] NetScaler is a box at the edge of a company network that checks who is allowed to log in. The flaw lets an attacker past that check without a password. [7] Citrix released a fix on 19 August, and attacks began on 3 September, a day after attack code was posted online. [7]

    Why it matters — US federal agencies now have three days to install the fix. [7] Any company that has not installed the August fix has been open to these attacks since 3 September. [7]

  6. 07

    A backup tool for websites was already under attack

    Acronis, a company that makes backup software, released an urgent fix on Tuesday for its backup plugin for cPanel, a control panel many web hosts use to run websites. [8] Wrong file permissions let an attacker who already has a small foothold on the server give themselves full control. [8][9] Acronis says the flaw has been used in a few targeted attacks. [8] It has not said who was attacked or since when. [9]

    Why it matters — Acronis told every user of the plugin to install the update immediately. [9] The same flaw exists in Acronis's tool for Plesk, another control panel, but no attacks on that version have been seen. [8]

  7. 08

    Meteor watchers' website knocked offline

    The International Meteor Organization, a Belgian group founded in 1988 that brings together amateur and professional meteor watchers, said a cyberattack dealt a critical blow to its ageing website. [10] Much of the site is offline, and the group expects several weeks of partial downtime while it moves to new systems. [10] It restored its fireball reporting form first. [10] No hacking group had claimed the attack. [10]

    Why it matters — The organisation keeps a database of photos, videos and telescope readings of meteors that scientists use. [10] Space research groups have been attacked before, including two observatories in Hawaii and Chile in 2023. [10]

  8. 09

    An attack costs a company $52,000 on average

    Hiscox, an insurance company, published its yearly survey of 6,800 people responsible for security at firms in the UK, Europe and the US on 15 September. [11] Firms that were hit lost about $52,000 per attack on average, and $134,138 in Italy. [11] Systems were down for 32.8 hours on average. [11] British firms were the most likely to report a successful attack, at 38%, and American firms the least, at 20%. [11]

    Why it matters — The damage reaches staff as well as budgets: 69% of victims reported burnout or high stress afterwards. [11] Firms now spend about $51,000 a year trying to prevent attacks, close to the cost of one attack. [11]

  9. 10

    Security firms move to a new UK test

    SE Labs, a testing company in London, launched PIVOT on 15 September, a six-month test of how well security products stop real attack groups. [12] Its staff copy the methods of known hacking groups and follow each attack from start to finish. [12] Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos have signed up, and results are due in January 2027. [12] The best-known test until now, run by the US research group MITRE, fell from 30 companies in 2023 to 11 in 2025. [12]

    Why it matters — Companies buying security products have few independent ways to tell which ones actually stop an attack. [12] Microsoft, SentinelOne and Palo Alto Networks pulled out of MITRE's 2025 test after it was made harder. [12]

02 Lesson why it matters

Telling an attacker you saw them can stop the next attack

Britain and Norway showed Russia they had watched its submarines rehearse, because a plan the other side knows about costs more to carry out.

The twist

Fixing a hole stops one attack. Telling the attacker you saw it can make the next attack cost them more, because their method or their name is now known.

How it works

  1. An attacker's plan works only while the other side does not know about it
  2. Defenders who spot it can quietly fix the hole, or say publicly that they saw it
  3. Saying so tells the attacker their method, tools or money trail are now known
  4. A known method is easier to block, and a known person is easier to catch
  5. So the attacker has to pay for a new method, or decide the attack is not worth it

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • Russia's cable rehearsal near Svalbard

    Britain and Norway took what they had seen to Russia's government, hoping that a weapon Russia knows has been spotted is one it is slower to use.

  • The NightmareStresser seizure

    In an earlier round of seizures in April, European police identified about 75,000 users of sites like it, so taking a site warns its buyers as well as its owners.

  • The Roblox accounts case

    Investigators traced about $54,000 of cryptocurrency into the suspects' own bank accounts, the step that turned an anonymous shop into three named men.

  • The tanker boardings

    The two agencies went aboard in person and then said so in public, so whoever broke in now knows the ships' systems have been examined.

Where you've seen this

Shop security cameras

a visible camera stops some theft before any footage is ever watched

Speed cameras

drivers slow down where they know a camera is, whether or not it is switched on

Exam invigilators

a teacher walking the room prevents more copying than one who only checks papers afterwards

The catch

It only works on someone who fears being caught. A gang working from a country that will not arrest it can simply open a new website, as NightmareStresser's owners did after losing an address in 2022.

And the whole of it

A tanker crew, a child with a Roblox account and a volunteer who runs a meteor website cannot watch for attackers themselves. They rely on coast guards, police and testers they will never meet to notice, and to let the attackers know they were seen.

03 Truth what's really going on

What is really going on

Two tankers bound for US ports showed signs in August that their computer networks had been broken into, and US agencies boarded both ships at sea, three days apart. The US Coast Guard and the FBI confirmed it only on 16 September, after Bloomberg had reported it, and neither has said who did it or what the attackers could control. [1][2]

Why it works on us — A ship's engine being tampered with is a frightening picture, and the only source for it is one crew member quoted by a news agency backed by Iran's government, which is itself a side in the war the attack may be linked to. [1]

Who gains

  • The US Coast Guard — A 2024 order gave it more power over cyberattacks on ships and ports, and boarding two tankers shows it using that power in public. [2]
  • Buyers of stolen Roblox accounts in Russia — From May 2025 to April 2026 they could buy another player's account, with its game money and rare items, for about 80 US cents. [5]
  • Local police forces in the US — The GUARD Act would let them spend existing federal grant money on scam experts and tools that trace cryptocurrency. [6]
  • SE Labs, a London testing company — As big security firms pulled out of MITRE's test, five of them, including CrowdStrike and Palo Alto Networks, signed up to its new one. [12]
  • Norway and Britain — They confronted the Russian submarines and showed Russia's government what they had seen, and no cable was damaged. [3]

Who pays

  • Crews of tankers heading for the US — They sail on ships whose networks were broken into, and so far nobody has said who did it or how. [1][2]
  • Children and teenagers who play Roblox — About 610,000 of their accounts were taken over through stolen login files and sold on. [5]
  • Victims of crypto scams in the US — Americans lost $11.4 billion to these scams in 2025, and many were told their losses were too small for federal agents. [6]
  • Companies that have not installed Citrix's August fix — Attackers have been getting through their NetScaler gateways since 3 September, a day after attack code was posted online. [7]
  • Meteor scientists and amateur watchers — The International Meteor Organization expects weeks of partial downtime, with only its fireball reporting form restored so far. [10]
  • Staff at attacked companies — In Hiscox's survey, 69% of victims reported burnout or high stress after an attack. [11]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    What the attackers could actually do on board the tankers.

    A crew member told Mehr the engine speed was raised and a fuel tank switched off, while the Coast Guard and FBI say there were no operational disruptions. Neither account can be checked from outside. [1][2]

  • 02

    Who broke into the tankers.

    Investigators are reported to be looking at Iran or another group using the Iran-US war as cover, no group has claimed it, and the Coast Guard would not answer questions about it. [1][2]

  • 03

    Whether the second boarded ship is VL Prosperity or a different tanker.

    The Coast Guard did not confirm which ships it boarded, and only one tanker has been named, by Bloomberg. [1]

  • 04

    Whether anyone was arrested when NightmareStresser was seized.

    The US Justice Department announced the takedown but declined to say, and the site had already survived one seizure of its address in 2022. [4]

  • 05

    How the Russian weapon seen near Svalbard works.

    The only account comes from two unnamed Western officials, who declined to describe the technology, and Russia denies any sabotage. [3]

  • 06

    Who was attacked through the Acronis backup plugin, and for how long.

    Acronis says only that the attacks were limited and targeted, and has not said when it detected them. [8][9]

  • 07

    How many companies are still running NetScaler without the August fix.

    CISA has not described the attacks it has seen, and Citrix has published no count of unpatched systems. [7]

  • 08

    Whether the GUARD Act becomes law.

    It passed the US House of Representatives, and the US Senate has not voted on it. [6]

04 Hope carry this

The US Justice Department seized NightmareStresser, a website with more than 550,000 users that rented out attacks against schools, government agencies and gaming platforms.

Also true today

  • Three men accused of stealing and selling about 610,000 Roblox game accounts, most of them used by children and teenagers, are in custody in Ukraine and will stand trial.
  • Russian submarines practising with a weapon to disable Arctic internet cables were tracked by Britain, Norway and the US, and left without damaging any cable.
  • The US House of Representatives passed a bill from members of both main parties that lets local police spend federal grant money investigating financial scams.

Across the beats