The immediate backdrop is the ongoing March 2026 U.S.-Israeli military campaign against Iran, launched in early March when U.S. and Israeli forces struck Iranian power plants, air-defense sites and military infrastructure; Iranian military actions throughout 2026 have been described by officials as responses to that coordinated campaign.
Those strikes came after a year of escalating confrontations between Iran and Israel and a steady intensification of U.S. pressure on Tehran, setting the operational environment for the region’s maritime and cyber tensions.
U.S. officials are investigating whether Iran or an Iran-aligned actor carried out cyberattacks that compromised two energy tankers — an oil tanker and a liquefied petroleum gas carrier — while they transited the Strait of Gibraltar en route to ports in Texas, according to reporting based on U.S. officials (per jpost.com).
The probe centered on forensic examinations of the ships’ information-technology and operational systems after authorities detected signs the vessels’ networks had been breached; specialized teams from U.S. Coast Guard Cyber Command and FBI agents boarded both ships and inspected systems for three to four days, Rear Adm. Amy Grable said (per jpost.com).
U.S. investigators are treating the incidents as potentially widening Iran’s toolbox for attacking global energy shipping beyond traditional Middle East maritime flashpoints, the reporting says (per jpost.com).
Officials cited by the Wall Street Journal and summarized in the jpost.com account flagged concern that Tehran or Iran-aligned actors may be experimenting with cyber means to disrupt energy flows to the United States (per jpost.com). The ships were routed to American ports in Texas after the events and then boarded by U.S. cyber response teams for forensic work (per jpost.com).
State or private sector statements assigning definitive responsibility have not been published in the cited account; the report presents the investigation and the involvement of Coast Guard Cyber Command and the FBI as the most concrete, verifiable actions taken so far (per jpost.com). Rear Adm.
Grable’s on-board timeline — three to four days of assessment — is the most specific operational detail available in the reporting and is the basis for U.S. officials’ immediate confidence that they secured the vessels’ ability to continue to port (per jpost.com).
Why now: the probe follows apparent intrusions detected while the vessels were in the strategic Strait of Gibraltar, a chokepoint for energy traffic to and from the Atlantic; U.S. officials worry that cyber operations could expand asymmetric pressure points against energy shipments bound for the United States (per jpost.com).
Confirmed: teams boarded the ships and conducted multi-day examinations; claimed but unproven in the published reporting: Iran’s direct responsibility (per jpost.com). What comes next is likely further forensic work, interagency intelligence assessments and potential diplomatic or kinetic options if investigators conclude attribution meets U.S. standards (per jpost.com).
Whether U.S. investigators publicly attribute the incidents to Iran or an Iran-aligned actor after completing forensic analysis by the end of the interagency review (per jpost.com). 2) Whether the U.S. Coast Guard Cyber Command issues new guidance or mandates for foreign-flagged vessels transiting the Strait of Gibraltar bound for U.S. ports within the next 30 days (per jpost.com). 3) Whether the Department of Homeland Security or the State Department raises the incidents with allied maritime authorities and shipping companies at upcoming security briefings this month (per jpost.com).