INDUSTRY

Exclusive: Korean-owned ship caught up in FBI probe into Iran hacking

by
Park Hye-won
Published : Sept. 19, 2026 - 06:00:00
    • Copy Completed!

View Korean Original

Hyundai Glovis-owned VLCC VL Prosperity among vessels under US scrutiny over suspected Iranian cyberattack; Korean firms seen unlikely to face penalties

[Herald DB]
[Herald DB]

Korean companies have been drawn into a US investigation of suspected Iranian hacking of a tanker that was entering a Texas port, industry sources confirmed Friday.

The US Coast Guard and the FBI recently obtained evidence suggesting that the very large crude carrier (VLCC) VL Prosperity — owned by Hyundai Glovis and managed by HMM Ocean Service — was the target of a cyberattack, and have launched a formal probe, according to industry sources.

As part of the investigation, US authorities contacted HMM Ocean Service with inquiries about the vessel's cybersecurity systems. Hyundai Glovis said it had reported signs of a malware infection before the ship set sail — including the deletion of some data — and that the vessel subsequently underwent a Port State Control (PSC) inspection by US authorities.

The ship had been carrying oil from Egypt to the United States when communications went dark for roughly 30 hours just before it anchored off the Texas coast late last month. US investigators believe Iran was likely behind the attack, possibly aiming to disrupt a major maritime shipping route or cause an incident at a US port.

The incident reflects a growing sense within the shipping industry that cyberattack risks, long discussed in theory, are now materializing. According to foreign media reports, a Liberian-flagged LNG carrier built by HD Hyundai Samho and managed by H-Line Shipping also suffered a suspected cyberattack earlier this month while transporting LNG in the United States, bringing its voyage to an abrupt halt.

"There have long been concerns that ships could become targets as hacking techniques grow more sophisticated, but this is the first time an actual incident has disrupted vessel operations in the way we are seeing now," a maritime cybersecurity expert said.

For the time being, however, Korean companies are unlikely to face liability over the security lapses. The International Maritime Organization (IMO), which sets the regulatory benchmark for maritime incidents, made cybersecurity technology mandatory last year but applied the requirement only to vessels contracted after July 2024. Most of the ships involved in recent hacking incidents are still under construction and therefore fall outside the scope of the regulation.

The more pressing concern is what happens when a hacking incident strikes a vessel built by a Korean shipyard or owned by a Korean shipping company after the IMO rules take effect. If a large commercial vessel is disabled by a cyberattack, delays in cargo movement and port-entry reporting could cause losses running into tens of millions of dollars per hour. Secondary accidents — such as collisions with other vessels — could expose companies to further damages.

Industry observers say Korean shipbuilders and shipping companies need to engage more actively in international regulatory discussions to prepare for such scenarios. "Korea leads the world in shipbuilding technology, but it has actually been passive when it comes to international forums like the IMO on cybersecurity," one industry official said. "Given the state of Korea's own cybersecurity capabilities, the industry needs to speak up more forcefully on questions of regulatory standards and implementation timelines."


klee@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ