Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

U.S. offshore oil and gas infrastructure is exposed to significant cybersecurity risks, but public evidence does not show that offshore production facilities have been broadly breached. The concern is that remotely connected operational technology (OT) helps monitor and control equipment across a large offshore network, while a successful incident could affect safety, the environment, production, transmission, and energy supplies.

What offshore infrastructure is at risk?

The U.S. Government Accountability Office (GAO) reported in November 2022 that more than 1,600 offshore facilities produce a significant portion of domestic oil and gas. These facilities rely on technology to monitor and control equipment remotely. The scale matters to national energy supply, though the facility count and national output figures below come from different sources and reporting periods.

Measure Figure Source and period
Offshore facilities More than 1,600 GAO, November 2022; facilities producing a significant portion of U.S. domestic oil and gas
Federal offshore oil production Approximately 668 million barrels Bureau of Ocean Energy Management (BOEM), fiscal year 2024
Federal offshore gas production Approximately 700 billion cubic feet BOEM, fiscal year 2024
Active oil and gas leases Approximately 2,227 leases on 12.1 million Outer Continental Shelf acres BOEM, as of April 1, 2025

BOEM reports that almost all of the FY 2024 federal offshore oil and gas production came from the Gulf of America. These figures describe the sector’s scale; they do not indicate how likely any one facility is to be attacked.

Why are offshore oil and gas facilities exposed?

Remote operational technology

Modern exploration and production use remotely connected OT to monitor and control physical equipment. Connectivity can expand the pathways an attacker might try to exploit. OT differs from ordinary office IT because its availability and integrity can directly affect physical processes and safety, not just access to information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Legacy systems and uneven protections

Some older facilities may rely on legacy OT with fewer cybersecurity protections than newer systems. That is a sector-level concern, not evidence that every older installation is vulnerable or that operators have the same controls. GAO’s November 2022 report described the risk as arising from threat actors, vulnerabilities, and potential impacts; it did not publish a facility-by-facility risk ranking.

Potential threat actors

GAO identifies state actors, cybercriminals, and others as potential threats. Attacks on energy organizations or pipeline operators can illustrate broader sector exposure, but they are not evidence that offshore oil and gas production facilities have been attacked.

How could a cyberattack affect offshore oil and gas production?

A successful incident could interfere with systems that monitor or control operations. Federal officials cited by GAO identified possible physical, environmental, and economic harm, as well as disruption to production, transmission, supply, and energy markets. These are potential outcomes, not reported consequences of a major cyberattack on an offshore production facility.

  • Operational disruption: Loss of access to monitoring or control functions could impede production or transmission.
  • Safety and environmental consequences: Interference with safety-relevant processes could contribute to physical harm or environmental damage.
  • Supply and market effects: A disruption affecting output or transmission could ripple into energy supplies and markets.

GAO’s risk assessment does not provide an attack probability for a specific facility or a single expected-loss estimate for the U.S. offshore sector. The scale of possible consequences should not be mistaken for evidence that a worst-case event has occurred.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is there evidence of cyberattacks on offshore facilities?

Public information about confirmed incidents is limited. GAO reported in November 2022 that none of the federal officials or industry representatives it interviewed were aware of cyberattacks against offshore oil and gas infrastructure. In the same review, however, GAO identified two reported incidents:

  • 2009: An indictment alleged that a person temporarily disabled a leak-detection system for three offshore derricks. An indictment is an allegation, not by itself a finding of guilt.
  • 2015: A report described malware unintentionally introduced onto a mobile offshore drilling unit.

GAO cautioned that these examples did not come from a formal, comprehensive review of incidents. Its finding that interviewees were unaware of attacks therefore does not establish that no incidents have occurred. Nor do the two examples establish widespread compromise or a pattern of successful attacks.

What has the U.S. government done about the risk?

In its November 2022 report, GAO recommended that the Bureau of Safety and Environmental Enforcement (BSEE) develop and implement a cybersecurity strategy. The recommendation called for a risk assessment; objectives, activities, and performance measures; defined roles, responsibilities, and coordination; and identification of needed resources and investments.

GAO’s recommendation record says BSEE completed a strategy and began implementation, including initial hiring work and a tabletop exercise with federal partners. In status information reported through February 2026, BSEE said it had completed a position description for a cybersecurity program manager, was developing a communications plan, and had drafted an update to its Safety and Environmental Management Systems rule. BSEE anticipated proposing that update in summer 2026 and additional cybersecurity proposals in fall 2026. Those dates are agency-reported plans; the record does not establish that the proposals were completed. BSEE’s own topic page says more than 1,000 oil and gas facilities fall within its purview and describes cybersecurity challenges on the Outer Continental Shelf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does Coast Guard maritime cybersecurity regulation fit in?

In 2026, the U.S. Coast Guard announced policy and work instructions to support regulated maritime entities’ compliance with cybersecurity regulations under 33 CFR Part 101, Subpart F. The Coast Guard describes cybersecurity assessment as a foundational step in continuous maturity. This maritime framework should not be read as one comprehensive cybersecurity rule for offshore oil and gas production facilities; it addresses regulated maritime entities in its own scope.

A separate Associated Press report dated September 16, 2026, said FBI and Coast Guard investigators responded to reported network breaches of two foreign-flagged commercial oil tankers in the Gulf of Mexico and boarded both vessels to assess possible harm to their IT and OT systems. Officials said there was no operational disruption, vessel instability, physical danger to crews, or environmental impact at that time. The vessels were tankers, not offshore production facilities, so the investigation is not evidence of an attack on offshore oil and gas infrastructure.

How should sector-level risk be interpreted?

GAO’s conclusion is that offshore oil and gas infrastructure faces significant and increasing cybersecurity risks. That is a sector-level warning about exposure and possible impact, not a forecast that an attack will occur or proof that a particular operator has been compromised. Publicly available evidence does not establish comparable facility-specific probabilities, expected losses, or a basis for ranking operators.

To assess a particular claim about offshore cyber risk, distinguish documented incident evidence from scenarios, and check whether the claim identifies the affected asset, the operational consequence, and the evidence behind it. Remote connectivity, legacy technology, response coordination, and the quality of a risk assessment are relevant factors, but they do not alone prove that an individual facility is insecure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.