Weekly Security Brief

Week of Sunday, September 6, 2026

29 weeks of continuous coverage

Key Insights

1. Two Wars, One Barrel

The national average price of diesel hit $5.85 a gallon this week, an all-time high, and two separate wars, thousands of miles apart, are why.

Iran is short of gasoline, and has been for years. The country burns roughly 34 to 36 million gallons of gasoline a day and refines only about 32 to 34 million. That gap predates the current crisis, and it showed up in the numbers weeks before the queues started forming in late August.

The war made it worse. Between February and April, Israel and the United States' joint campaign against Iran hit four gas-processing units at South Pars, the offshore field that supplies most of Iran's natural gas, knocking out roughly a third of the field's output. Total war damage to Iran's economy is estimated at $145 billion, with refineries and the fuel network among the direct casualties.

Iran had been covering part of its own shortfall by importing refined gasoline from Russia, shipped south across the Caspian Sea, the inland sea the two countries share. That backup channel is now closing. Russia banned its own gasoline exports in April. Ukraine then spent the year hitting nearly every major Russian refinery with long-range drones, cutting Russian fuel production to a 24-year low. In July, Russia extended its export ban through January 2027. Between the ban and the lost capacity, there's simply less Russian fuel reaching any buyer, Iran included.

On the ground in Iran, that means mile-long gas station lines in Tehran since late August, stations closing, and gasoline selling openly on the black market.

Diesel is a globally traded commodity: when Russian and Iranian fuel both tighten at once, buyers everywhere else are bidding for the same barrels that are left. On top of that, tankers moving fuel through the Gulf now carry war-risk insurance premiums that didn't exist two years ago. Marine war-risk claims have already passed $2 billion this year, more than insurers expected to collect for the entire year on that coverage, and that added insurance cost is baked into what you pay, not just the price of the fuel itself. Don't expect relief from the recent US-Venezuela oil deal either: that oil is earmarked to refill the US Strategic Petroleum Reserve, not the commercial market, so it won't show up at a gas station anytime soon.

The Takeaway
These are two separate conflicts with two separate sets of combatants, thousands of miles apart. But they're both landing on the same global fuel market at the same time, which is why the price at the pump doesn't have one simple explanation. Russia's export ban alone runs through January, so this isn't a one-week spike.
Sources: Iran International: fuel shortage figures · Bloomberg via Yahoo Finance: Iran fuel shortages spark lines · IranWire: Iran loses one-third of South Pars gas production capacity · Al Arabiya: Iran's $145 billion war losses · Al Jazeera: Russia bans gasoline exports · Critical Threats: Iran Update, September 1 · Critical Threats: Iran Update, September 3 · Euronews: kilometer-long petrol queues in Iran · Moscow Times: Russian refining falls to 24-year low · Moscow Times: Russia extends fuel export ban through January 2027 · Iran International: Russia's gasoline imports add pressure to Iran's fuel market · NPR: diesel hits record high · NBC News: diesel hits all-time high · gCaptain: war risk claims top $2 billion as shipping attacks spread beyond Hormuz · NPR: Trump says US will refill Strategic Petroleum Reserve with Venezuelan oil

2. The Cheapest Way to Take Down a Power Grid

A timer, a length of copper wire, and a homemade rocket. That's what it takes to black out a substation, and German police just found the third such device in a week.

Police pulled a homemade rocket rig off the grounds of the Dormagen substation, a chemical-manufacturing hub between Cologne and Düsseldorf, on Thursday evening. The device carries a length of copper wire up and over high-voltage lines; the wire touches a live conductor to the ground, and the resulting short circuit trips the substation. No explosives needed, no technical training required, and the materials probably cost a few hundred dollars. It's the third device found at a German energy site in a week, after Bergheim, a coal-mining region nearby, and Jänschwalde, one of Germany's largest coal-fired power plants, where more than a dozen similar devices turned up earlier in the week. Investigators received a letter claiming responsibility for all three as one ongoing campaign, allegedly signed by a man citing opposition to the fossil-fuel industry.

Germany's government has separately and formally attributed a different attack, a drone strike in the Leipzig/Halle area, to Russia. Germany is a NATO member, and a state-directed drone strike on its own soil is a serious escalation, not routine sabotage. That leaves an uncomfortable open question hanging over the substation devices too: is the confession letter genuine, or could a state actor be using a "lone domestic activist" story as cover for its own sabotage, deliberately muddying who's responsible?

A substation going down at a chemical-manufacturing hub isn't just a lights-out problem. Chemical plants run continuous processes that can be damaged or ruined if power cuts out mid-batch, and the equipment inside a substation, particularly large transformers, is often custom-built to that site's specifications rather than sitting on a shelf somewhere. When a piece like that is damaged, replacing it can take months, not days. Insurers price coverage on how often something is expected to happen, so more incidents like this make that risk more expensive to insure and more expensive to prevent, and that cost gets passed down to everyone who depends on the grid.

The Takeaway
A device built from parts anyone can buy just blacked out a piece of critical power infrastructure for the third time in a week, and the equipment behind that outage isn't something you replace overnight. For a factory that runs on a continuous process, reliable power is increasingly a question of what you can generate yourself on-site, not just what the public grid promises to deliver.
Sources: t-online: Umspannwerk in Dormagen — Bekennerschreiben aufgetaucht · Defense News: German government blames Russia for Leipzig airport drone attack

3. They Verified Your ID. Then They Kept It.

When did you last hand your driver's license to a rental-car counter, a retail checkout, or a venue door? The scan doesn't disappear after that transaction. It may still exist, and as of last week it may have been for sale.

IDScan.net verifies IDs for companies at checkout counters, rental desks, and secure doors, telling real licenses from fakes. It processes more than 21 million verifications a month across more than 20,000 locations. Its client list, per its own website, includes Hertz, Target, FedEx, Motorola Solutions (the radio maker used by police and fire departments), Jack Henry, whose core banking software runs behind the scenes at thousands of community banks and credit unions, the Planet13 dispensary chain, and Caesars Entertainment, which says it stopped using the service in February 2025.

That last detail matters more than it looks. If a company stopped using IDScan.net over a year ago and its customers' scans are still turning up in this breach, dropping a vendor didn't get anyone's old data deleted. Whatever IDScan.net collected while a client was still using it appears to have stayed on IDScan.net's own servers indefinitely.

Krebs on Security broke the story and confirmed it was real, not just a criminal's claim: he found his own driver's license and his mother's in the stolen data, matched the timestamps against actual travel records, and heard from nine other people who found themselves in it too. On August 31, a dark-web listing called "Nexus" opened selling more than 153 million U.S. and Canadian driver's license scans, each one including the front, back, and the security-check images used to catch counterfeits, plus more than 10 million ID cards, 3 million travel documents, and 579,000 medical cards. The listing grew by nearly 400,000 records in its first day and went offline after the story ran. The FBI's New Orleans field office has opened an investigation. IDScan.net's only public comment, from a spokesperson, was that the company couldn't share additional information beyond confirming an active investigation. It hasn't explained why it kept the images at all, and there's no securities filing to check since it isn't a public company.

Here's the part that should worry anyone who relies on an ID check to know who they're dealing with. A verification scan exists specifically to catch a fake, which means the stolen copies carry the same security markers a real license has. Someone with this data doesn't need to forge an ID from scratch. They can produce one that would pass the exact check it was built to defeat, with a real person's real information on it, and there's no clean way to prove that ID is fraudulent once it looks and scans exactly like the one that was actually issued.

The Takeaway
Hertz's customer handed their license to Hertz, not to IDScan.net. But Hertz, and everyone else on that client list, outsourced the actual verification to a vendor three steps removed from the transaction. That's the liability every company on the list is about to learn the hard way: when your ID-verification vendor keeps data it doesn't need, your customer's lawsuit names you, not the subprocessor they've never heard of. Any contract that hands a vendor identity documents needs to spell out that the data gets deleted after verification, and somebody has to actually check that it does.
Sources: Krebs on Security: FBI probes service selling 153M driver's licenses

4. The Breach Nobody Was Warned About, Twice

Ceva Logistics suffered a ransomware attack in September 2025 that it never disclosed. Ten months later, on July 29, 2026, it happened again, this time much bigger, and a former employee's lawsuit says the first attack should have been the wake-up call that prevented the second.

Ceva is one of the largest freight and contract-logistics providers in the world, owned by the French shipping group CMA CGM, which is privately controlled by the Saadé family and isn't listed on any public exchange, so there's no SEC filing that would have forced any of this into the open. A leak-site screenshot is the only public record of the September 2025 attack, attributed to a ransomware group called CoinbaseCartel; Ceva never disclosed it.

The July 29, 2026 intrusion was much bigger and hit two things at once: the systems running eight of Ceva's European warehouses, which disrupted order fulfillment for online retailer bol.com, gaming platform Steam's European hardware sales, Dutch department store De Bijenkorf, eyewear brand Ace & Tate, and Amsterdam football club Ajax's merchandise store, and a broader employee database covering current and former staff across the company, which is how a former employee living in Michigan ended up exposed even though the warehouses that were hit were in Europe. Ceva confirmed the intrusion to affected customers on August 1. It has not, according to the lawsuit, formally notified the employees whose data was exposed, which reportedly includes names, Social Security numbers, home addresses, dates of birth, bank account details, salary and pension information, copies of ID cards, details of employees' partners and children, and notes from individual performance meetings, though not every category was exposed for every person.

Kevin Krupa worked at Ceva from 2007 to 2024, so he'd already been gone for close to a year before either breach happened, and his personal data was still sitting in Ceva's systems for both. He filed a proposed class action (*Krupa v. CEVA Logistics*, No. 4:26-cv-07007, S.D. Tex.) on August 24, 2026, on behalf of himself and everyone else affected. According to the complaint, Krupa found out the way most victims do when a company stays quiet about the details: not from a real notice, but from fraud showing up on his own accounts, unauthorized credit-card charges that forced him to cancel the card, and a spike in scam calls. The complaint argues Ceva failed to train employees on cybersecurity and failed to maintain reasonable safeguards, and specifically points to the September 2025 attack as proof Ceva already knew the risk and did nothing about it before the much bigger breach ten months later. It brings claims for negligence, breach of implied contract, and unjust enrichment, plus a request for a court order forcing Ceva to strengthen its security, submit to annual audits, and pay for lifetime credit monitoring for everyone affected. It seeks class-action status for at least 100 people, potentially thousands, and damages north of $5 million.

Around this same period, Ceva's VP of IT Infrastructure for the Americas left the company about two months after the first attack, its chief information officer departed the following spring, and CMA CGM moved Ceva's own CEO, Mathieu Friedberg, into a new transformation role at the parent company that also covers cybersecurity. Nobody has officially tied any of this to either breach, but three senior leadership changes touching security and technology, spanning the same stretch when the company was quietly sitting on one undisclosed attack and then suffered a much bigger one, is a hard coincidence to take at face value.

A third-party logistics provider holds your shipping manifests, your customers' addresses, your inventory counts, and often a live connection into your order system, on top of its own employees' HR files. The law generally says its duty to notify runs to the people whose data was stolen, not to the businesses that rely on it, like you. Here, apparently, it didn't even do that: the lawsuit says Ceva never formally notified Krupa or the other affected employees either.

The Takeaway
Ceva had a ransomware attack in 2025 and kept it quiet. Ten months later it had a much bigger one that hit both its warehouse operations and its employee records at the same time, and an actual lawsuit now argues the second breach was preventable because the first one should already have forced a fix. If a company you rely on has an incident and stays quiet about the details, the lesson isn't that the risk went away. It's that you won't find out how bad it actually is until something worse happens and somebody sues.
Sources: FreightWaves: Ceva Logistics sued over theft of employee records · TechCrunch: a data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond · The Record: Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe · Cybernews: CEVA Logistics data breach exposes employee records

5. Companies With Five Employees Asked to Import $130 Billion

Algeria's trade ministry says a digital platform with what it calls "AI functionality" caught three different kinds of import fraud in one week. What's actually behind that label is unclear: the government hasn't named a vendor or said whether this is genuine machine-learning analysis or standard data-matching software wearing an AI label.

Algeria requires importers to file forecast import programmes, a declaration of what they plan to bring in, before goods clear customs. The declarations run through a digital platform the ministry describes only as having automated cross-referencing and "AI functionality," with no vendor named and no detail on what technology is actually doing the matching. Within days of processing this cycle's filings, it surfaced three separate problems. On September 2, it flagged 1,013 companies sharing 1,093 identical documents, paperwork that's supposed to be unique to each company. A day later, a second pass found 581 companies claiming the same geographic coordinates for their production sites, tracing back to entities that don't appear to be real businesses. Then on September 5, the ministry disclosed the biggest number: nearly 4,000 companies with fewer than five registered employees had filed import requests totaling $130 billion for just the second half of 2026, a scale wildly out of proportion to their declared size. Investigators also found a pattern of companies declaring employees from January through March, dropping those declarations from April through June, then re-registering the same workers from July through September, exactly when the next import application window opened.

The ministry hasn't said what happens to any of these companies yet. It says only that "the necessary measures will be taken in light of the results" of a verification campaign, which will now compare each flagged company's declared import needs against its actual production capacity, workforce, and financial performance, and will also look back at the first half of 2026 and prior years, not just this filing cycle. No company or executive has been named.

The Takeaway
Call it AI or call it well-built data-matching software, something is clearly working here: three unrelated fraud patterns, caught by cross-referencing data the government already had against itself, before a single company has actually been penalized. Whether this represents a real leap in automated detection or just a better-marketed version of tools that have existed for years, it's worth watching as a sign of where procurement and vendor screening are headed, and whether your own systems are anywhere close to doing the same thing.
Sources: TSA: PPI imports — ministry reveals over 1,000 duplicates · Algérie Eco: 1,013 operators, similar files · Algérie Eco: digital audit reveals identical geolocations, fictitious companies · Algérie Eco: nearly 4,000 operators declare $130 billion in needs · TSA: investigation into 4,000 micro-enterprises suspected of import fraud

6. The Banking Crisis Behind the Clothes You're Wearing

Bangladesh makes more of the world's clothing than any country except China, and a third of the banks financing that industry are buried in bad loans.

When a Bangladeshi factory takes an order from a Western retailer, it borrows from a local bank to buy fabric and pay workers, since it doesn't get paid itself until months later when the finished goods ship. The retailer's own payment promise, called a letter of credit, also runs through that same local bank. That financing chain is what's now under strain, and the cost of it eventually lands somewhere in what a garment costs on a store shelf.

Roughly a quarter of Bangladesh's banking sector is made up of Islamic banks, which operate under religious rules that forbid charging interest and structure loans around shared profit instead, but otherwise function like any other bank: they take deposits and lend the money out. Bangladesh's central bank reported in July that 58.4 percent of these banks' loans had stopped being repaid as of March, up from 29.2 percent a year earlier. A meaningful share of that bad debt traces back to loans tied to S Alam Group, a large, politically connected Bangladeshi conglomerate accused of years of loan irregularities, now surfacing as unpayable debt across several banks at once.

The clearest sign of how bad it's gotten: in June, depositors at Islami Bank Bangladesh, the country's largest private bank, pulled roughly $350 million in a single week after its chairman and CEO abruptly resigned, and $1.75 billion over the quarter. The government's response was to dissolve the bank's entire board. Separately, five other troubled Islamic banks were already merged last year into a new bank called Sammilito Islami Bank, whose depositors are now being told they'll get their original money back with no interest or profit, starting this week, while the government hunts for an outside investor to rescue it.

The Takeaway
This isn't just a story for companies that buy directly from Bangladesh. A meaningful share of the world's clothing and textile supply runs through this banking system, and when the banks financing that production are this strained, the costs and disruptions eventually show up somewhere down the chain, whether that's a delayed shipment, a factory that can't get working capital, or a slightly higher price tag on the shelf.
Sources: Daily Star: Islamic and fourth-generation banks buckle under NPL and liquidity crises · Dhaka Tribune: mass depositor withdrawals trigger liquidity crisis · Dhaka Tribune: board-less Islami Bank struggles · TBS News: government seeking strategic partner for Sammilito Islami Bank

7. The Junta That Escaped Foreign Control Just Needed a Foreign Army

Niger's military government seized power in 2023 promising to reclaim the country from foreign influence. Three years later, it only survived a mutiny because a different foreign power's soldiers fought to keep it in charge.

A junta, a government run by military officers who took power by force rather than through an election, has ruled Niger since a 2023 coup led by General Abdourahmane Tiani. On August 29, mutinous soldiers attacked several military sites in the capital, Niamey, and seized the airport's Air Base 101 overnight. The junta couldn't retake it on its own. It called in Russia's Africa Corps, a paramilitary force built from the remains of Wagner after founder Yevgeny Prigozhin died in a plane crash in August 2023, widely seen as a Kremlin assassination after he'd turned his own mercenaries against Moscow's military leadership two months earlier. Africa Corps fighters provided the ground and air support that retook the base, and Russia's own ambassador in Niamey confirmed the intervention.

Russia has had Africa Corps personnel in Niger since 2024, after the junta broke with France, its former colonial ruler, and pushed out the more than 1,000 US troops previously stationed there, the second-largest American military presence anywhere in Africa at the time. Officially, Africa Corps is there to fight jihadist insurgents active across the region. Analysts who study the group describe its real function differently: one called it "this praetorian guard service, to protect the regime," and another said its central mission is making sure the government it's protecting survives whatever comes at it. The junta seized power arguing it would free Niger from foreign control. It now depends on a foreign military force to stay in power at all.

That same government is also sitting on a separate, unresolved dispute: it seized the Somaïr uranium mine, majority-owned by Orano, a French nuclear-fuel company that's about 90 percent owned by the French government, and is trying to sell a stockpile of more than 1,000 metric tons of yellowcake, partially processed uranium ore. An international arbitration court has ordered that none of it be sold or transferred until the dispute is resolved. Yellowcake isn't weapons material on its own; it has to go through industrial enrichment, something only a handful of countries can actually do, before it becomes reactor fuel or anything close to bomb-grade uranium. So this is fundamentally an energy and sovereign-resource story, not a proliferation one, unless whoever eventually buys it already has serious enrichment capability of their own, and nothing in the reporting suggests that's the case here.

The Takeaway
Nothing in this week's reporting says Niger's uranium is headed to Russia specifically. But Niger has two problems right now: an unstable government and a stockpile of uranium it legally can't sell. Russia is the only outside power that has shown up not caring about the rules on either one.
Sources: France 24: Niger's thwarted mutiny highlights junta's dependence on Russia · Critical Threats: Africa File, September 3 · Mining.com: Niger junta seizes Orano's uranium mine · FPRI: why Niger can seize uranium but cannot sell it · Orano: The ICSID Arbitral Tribunal Opposes the Sale by Niger of Uranium Produced by Somaïr

Get this brief in your inbox every Sunday.

No tracking. No spam. One email per week.

Subscribe

Past Briefs

View all briefs →