Reported cyberattacks on two Texas-bound energy tankers last month prompted one of the state’s top energy officials to urge oil and gas producers, pipeline operators, and other energy companies to boost their own cybersecurity defenses.
Texas Railroad Commission Commissioner Wayne Christian said in a news release Thursday that the state’s position as a global energy leader makes its vast energy infrastructure “a prime target for foreign adversaries.”
“When the cost of hesitation exceeds the cost of preparation, common sense says we act now to protect vital energy infrastructure from cyber threats,” Christian said. “We must invest, test, monitor and strengthen our defenses now, before adversaries like China or Iran exploit a weakness and disrupt America’s energy security.”
Despite the agency’s name, the three-member Railroad Commission primarily regulates the state’s $385-billion oil and gas industry. This spring, it notified the companies under its purview that their internet-facing devices, including the heavy-duty computers known as programmable logic controllers, were particularly vulnerable, “potentially causing operational disruption and financial loss.”
“Some organizations in critical infrastructure sectors have already experienced disruptions caused by malicious interactions with the project files and the manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the warning, issued by the federal Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency, stated.

The cyberattacks on the Texas-bound tankers reportedly happened last month near the Strait of Gibraltar. (James Manning/PA Images/Getty Images)
Last month, two tankers near the Strait of Gibraltar, one carrying 2 million barrels of oil and the other an undisclosed amount of liquefied natural gas, were attacked while en route to Texas, according to multiple reports. The communications system on one of the ships, the oil tanker VL Prosperity, was reportedly disabled for 30 hours after the attack.
U.S. national security officials have not identified who they believe to be responsible for the attacks, although initial reports of the attack on the Prosperity came from an Iranian news outlet, CBS News reported last week. The sophistication of that attack “points to a well-resourced threat actor with specific knowledge of maritime operational technology systems and their vulnerabilities,” Foreign Policy Journal reported.
“The Coast Guard is actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption,” a Coast Guard spokesperson told Chron in a statement last week, shortly after news of the attacks became widely known.
The Coast Guard “commends the extensive cooperation from the impacted vessel and continues to encourage maritime partners to proactively request anonymized cyber assistance,” the statement added.
Despite reports that the Liberian-flagged Prosperity had been headed for Galveston before being attacked, a Port of Galveston spokesperson told Chron the vessel was not expected to dock there.
More Gulf Coast
Business | Texas beer distributor reportedly closes coastal facility
Changes | Texas mall property with old ties to 49ers faces liquidation
| Latitude Margaritaville announces expansion to Texas coast
Cruises | Carnival opens bookings for new and massive Galveston cruise ship
For more Gulf Coast news and features from Chron, sign up for The Third Coast newsletter here.
This article originally published at Texas energy official warns of state’s vulnerabilities after maritime cyberattacks.
