Daily OT Security News: September 19, 2026

Today’s OT security headlines focus on maritime and energy-sector system failures, a surge in manufacturing ransomware, and new and ongoing guidance for medical-device cybersecurity in healthcare.

FBI, Coast Guard boarded hacked oil tankers heading toward US coast

U.S. Coast Guard and FBI cyber personnel boarded two U.S.-bound oil tankers in the Gulf of Mexico from August 21 to 24 after indications that both vessels’ networks had been compromised. Reporting on one vessel said the intrusion interfered with navigation, propulsion, and cargo-related systems; the agencies reported no operational disruption, safety or environmental impact, and attribution remained unclear.

Source: TechCrunch

Black Kite: Manufacturing ransomware surged in 2026, spreading beyond the US, with 1,183 victims through July

Black Kite’s 2026 Manufacturing & Distribution Ransomware Report recorded 1,183 publicly disclosed manufacturing ransomware victims from January 1 through July 29, 2026, 39.7% more than the comparable 2025 period and above the full-year 2024 total. The report describes more activity affecting mid-market and European manufacturers, alongside third-party and supply-chain exposure.

Source: Industrial Cyber

Health-ISAC sets nine-domain MedTech cybersecurity baseline to guide medical device procurement, deployment

Health-ISAC’s Medical Device Security Council published a MedTech Security Baselines paper identifying nine foundational cybersecurity capability domains for healthcare delivery organizations and medical device manufacturers to use in evaluation, procurement, deployment and lifecycle discussions. The resource is risk-based decision support rather than a certification standard and calls for documented compensating controls and healthcare-provider risk acceptance when device-native controls are impractical.

Source: Industrial Cyber

Where Healthcare Cybersecurity Stands in 2026

RunSafe Security’s 2026 Medical Device Cybersecurity Index found that 24% of surveyed organizations experienced an attack or exploited vulnerability involving a medical device, up from 22% in 2025; 80% of those respondents said the event had a moderate or significant effect on patient care. The article identifies third-party exposure, AI-assisted exploit development, legacy equipment, and the operational difficulty of patching and segmenting devices as continuing challenges.

Source: 24×7 Magazine

LNG Tanker Carrying US Cargo To Europe Turns Back After Crew Reports Suspected Cyberattack

The LNG carrier Vivit Africa LNG, carrying a U.S. cargo intended for Rovigo, Italy, experienced a systems failure while approaching Europe; the crew lost access to some internal control systems and reported a problem affecting cargo-parameter monitoring. The vessel did not unload off Italy and sailed toward Algeciras, Spain while the cause remained under investigation; Italian Coast Guard officials confirmed a systems malfunction but had not established that a cyberattack caused it.

Source: Marine Insight

Across maritime, manufacturing and healthcare, organizations should emphasize device visibility, firmware and certificate lifecycle controls, and service assurance when planning risk reduction and incident response.

Share this