Weekly Threat Brief

Week of Sunday, September 20, 2026

Key Insights

1. The Toll You Can't Legally Pay

Iran is now enforcing a blacklist inside the Strait of Hormuz with gunfire, collecting the toll in crypto, and running the whole apparatus through an organization it is a federal crime to pay.

On Friday, Iranian state media announced that Iran's Revolutionary Guard navy has drawn a restricted zone inside the Strait of Hormuz. Ships on the list can still sail through, but they lose access to maritime support and insurance services if anything goes wrong. Iran alone decides who is on the list, based on whether a ship coordinated its passage with Iran first. There is no rule published in advance that a shipowner can check. This is Iran's own account of its own policy, carried by its own state-aligned press; no outside source has confirmed the zone exists exactly as described. Western trade press has independently confirmed three separate tanker attacks hit the strait over the past three days.

The same force struck a Togo-flagged tanker, the Trend, on Wednesday night, saying it attempted illegal passage at the instigation of the US military. Iran has treated any transit it has not personally authorized as illegal since March, when the Revolutionary Guard declared the strait closed to unfriendly nations unless Iran approves the vessel first. That standard does not depend on a ship's flag, owner, or cargo. It depends on whether Tehran said yes, which means it can reach nearly any commercial vessel afloat.

The money side has a name now too. Treasury sanctioned BitBank, an Iranian cryptocurrency exchange, on Thursday for moving toll payments collected by an entity called Hormuz Safe into Iran's financial system. Treasury says the network moved hundreds of millions of dollars to the Revolutionary Guard between June and July alone. That closes a trap rather than opening one: the Revolutionary Guard, the same force running the list, has been on the US terrorist sanctions list for years. Paying the toll, or even asking to get off the list, means transacting with a designated terrorist organization under US law. There is no legal route through.

Saudi Arabia's own response shows how real this is. Aramco, the Saudi state oil company and the world's largest oil exporter, normally moves crude overland through its East-West pipeline to skip the strait entirely. An attack on that pipeline this month stopped that flow. Rather than wait for repairs, Aramco cut October crude allocations to at least two of its European term customers to zero and rerouted roughly 60 million barrels back through Hormuz instead. Sailing through a contested strait beat not shipping oil at all.

None of this points toward a resolution. The most likely path from here is more of the same: intermittent strikes, an expanding sanctions list, and oil producers routing through the risk because their alternatives are drying up, one pipeline at a time. Bank of America is watching for oil near $150 a barrel only if the fighting moves from ships and pipelines to oil fields and export terminals directly, a step beyond anything confirmed so far. Insurers underwriting war-risk coverage on these routes are the other number worth watching. When they move, before the headlines catch up, that is usually the clearest signal of where this is actually heading. This is not going to resolve soon. The list, the sanctions, and the workarounds will keep shifting for weeks, probably months, and it would not be surprising if it stretched into years.

The Takeaway
You do not need a ship or a shipping contract to feel this. Oil moving through Hormuz now carries a toll that cannot be paid without breaking US sanctions law, and the producers moving it are sailing through the risk rather than stopping. That shows up in your fuel bill, your freight costs, and the price of anything trucked, flown, or shipped to you. If you do move goods by sea, your contracts almost certainly cover a ship that's seized or blocked. Few cover one that's still sailing but denied a tug, a pilot, or salvage help when it needs one, which is exactly the gap this new toll system creates.
Sources: IRGC Navy restricted zone and vessel service-denial list (Hamshahri Online — Iranian state media, not independently verified) · Iran: IRGC Navy struck Togo-flagged tanker in Strait of Hormuz (Caliber.Az) · Three tanker attacks hit Hormuz as Saudi oil is forced back toward the strait (gCaptain) · US sanctions BitBank, crypto exchange tied to Iran's Hormuz Safe transit payments (gCaptain) · Saudi Arabia cuts Europe off from October crude after East-West pipeline attack (OilPrice)

2. Your AI Vendor Contract Was Written Before This Existed

Every cloud contract your company has signed for fifteen years splits responsibility the same way: the vendor secures the platform, you secure your settings. A new case shows that line has quietly moved to cover settings you never knew existed.

If your company uses any AI product that takes actions on its own, not just a chatbot that answers questions, but something that can run commands, touch files, or call other systems, you likely have a vendor contract somewhere with a shared responsibility clause in it. Legal almost certainly reviewed that clause for data ownership and liability caps. Almost nobody checked whether the vendor's own default settings could end up being your responsibility. This month, for the first time, a major vendor actually made that argument.

Amazon's AgentCore Harness, a platform used to run AI agents, ships with two tools switched on for every customer by default: one that runs system commands, one that edits files. Both run with full administrator access, in the same place the platform temporarily stores a customer's login credentials in plain, readable form. Security researchers at Unit 42 showed a real attacker could hide an instruction inside an ordinary customer support ticket, have the agent run it, and walk away with those live credentials, no password needed. When the researchers reported it in May, Amazon's response was to close the case as normal operation, not a flaw, because the setting involved is technically the customer's to change.

The Takeaway
Amazon is just the first vendor to make this argument in public where it could be checked; the incentive to make the same argument exists for every vendor selling AI agent products. If your company runs any AI product that acts on its own, the contract governing it was very likely reviewed for privacy and liability, not for which of the vendor's default settings you have quietly agreed to own. Whoever manages that vendor relationship should get, in writing, a list of which of the product's defaults the vendor would call your responsibility if one of them caused a breach.
Sources: Unit 42: Securing AWS AgentCore Harness Credentials

3. Nobody Owns the Return Shipment, and That's the Whole Problem

An F-35 canopy left Australia for a routine US repair and ended up in Hong Kong instead, and three months later nobody, not the Pentagon, not the manufacturer, not the shipping company that handled it, can say why or where it actually is.

In June, State Department and Pentagon officials quietly began briefing congressional staff that a shipment of F-35 parts, including a canopy built with the jet's stealth coating, had been rerouted to Hong Kong while in transit from Australia to the United States for repair. That was three months ago. The public only learned about it this week, when a news report broke the story. As of Friday, the shipment's location and custody were still unknown, nobody has said whether it was a mistake or done on purpose, and there is no public evidence Chinese authorities or the Chinese military have the parts. The Pentagon's F-35 program office says it is working to recover the components and investigate.

The reason this can happen to a US fighter program applies just as easily to an ordinary shipment your company sends out for repair or replacement. Every compliance program is built around the outbound sale: the purchase order, the paperwork, the approved buyer. The same scrutiny rarely applies to the trip back. Repair, warranty replacement, and demo units all move the same controlled item, and on that return trip, the actual route and carrier get picked by an outside shipping company you hire to handle the logistics, based on cost and speed, not on who is allowed to see what is inside the box.

The Takeaway
Find out, for anything valuable or sensitive your company ships out, whether that is overseas or across the country, whether it is equipment going out for repair, a warranty replacement, or a demo unit, who actually decides the shipping route once it leaves your dock. For most companies, nobody is watching that decision at all. If something ends up somewhere it should not, you may not find out until it is too late to do anything about it.
Sources: FreightWaves: Federal probe into diversion of F-35 parts to Hong Kong

4. Your Shared Vendor's Bad Day Is Your Bad Day

A shared compliance officer must now prove it can actually do the job for every client it serves, not just hold the title, under rules one regulator is already enforcing and separately tracks as a bigger risk to the entire banking sector.

Germany's financial regulator, BaFin, fined Volksbank Düsseldorf Neuss €210,000 this month for real anti-money-laundering failures: missed monitoring, missed follow-up on higher-risk relationships, and suspicious-activity reports filed late or not at all. The bank had outsourced its anti-money-laundering officer role to an external provider that served several other banks at the same time.

BaFin has been tightening the rules on exactly this kind of arrangement since 2024. Its stated reason is capacity: a bank using a multi-client provider for this role must now show that provider actually has enough staff to do the job for every client it serves, not just show that the title is filled. BaFin has also stopped accepting an anti-money-laundering officer based outside Germany even through a foreign parent company, a channel it used to allow, and it now classifies delegating this role as outsourcing a critical function, which pulls in a heavier set of risk-management requirements. Separately, BaFin runs a named program tracking concentration risk in outsourced IT and cloud services, the concern that a small number of vendors serving much of the banking sector means one vendor's failure can hit many banks at once. BaFin has not publicly tied that framework to the AML officer rules, but the same regulator already treats the pattern as a systemic concern elsewhere in bank oversight.

The Takeaway
Any company that relies on a shared vendor for a specialized function, IT security monitoring, background checks, a fractional compliance role, carries a version of this exposure: if that vendor is stretched thin or gets breached, every client feels it at once, often without learning the vendor was the common thread. If your business sits inside financial regulation, the bar already moved: your provider now has to prove it can staff your account, not just fill the title. Find out which of your critical vendors serves dozens of other companies, and what happens to you the day it has a bad one.
Sources: BaFin enforcement notice, Volksbank Düsseldorf Neuss eG

5. Russia Has Done This Before, and It Never Went Back

Russia just ran the same legal maneuver against four Western corporate groups at once that it used against Danone and Carlsberg in 2023, and in both of those earlier cases, temporary administration ended in a forced sale to a Kremlin-connected buyer, at a steep discount.

On September 17, Russia's government transferred day-to-day control of the Russian operations of Nestlé, Auchan, Leroy Merlin, and the European logistics firm FM Logistic to a company called LEV Management, a shell registered in Moscow in 2024 with about $150 in capital and no disclosed owners. Its general director, appointed one week before the decree, is Andrei Krayushkin. Novaya Gazeta Europe, an independent Russian investigative outlet, reports his name and birth date match a major general in Russia's interior ministry.

All four groups made some version of a bet to keep a foothold in Russia after Russia's 2022 invasion of Ukraine. Nestlé scaled back investment and pulled some brands but kept supplying food, saying it would not profit from the business. Auchan kept its roughly 230 stores running at full scale. Leroy Merlin's French parent announced its exit back in 2023 and sold the business, but the renamed entity, now called Lemana Pro, was still swept into this week's decree anyway, which suggests announcing an exit does not necessarily put a business fully outside Russia's reach. The Kremlin's spokesman gave the actual reason without naming names: the companies' home countries are unfriendly states most actively involved in military actions against Russia.

This is not a new legal tool. Russia used the identical mechanism, a 2023 decree allowing temporary administration of assets from unfriendly countries, against French dairy company Danone and Danish brewer Carlsberg's Baltika unit. Danone's Russian business was valued at $440 million. While it sat under state administration, a nephew of Chechen leader Ramzan Kadyrov, a close Putin ally, was installed to run it. About ten months after being seized, the business sold for $194 million, a 56 percent discount, to a Russian buyer reported to have ties to Kadyrov. Carlsberg's Baltika stake took longer, about a year and a half, before it too went to new Russian owners. Both ended the same way: a forced sale nobody on the Western side chose, at a price nobody on the Western side set.

The Takeaway
What this demonstrates goes well beyond Russia or retail: a government can take a foreign company's assets without declaring war on it, appoint an administrator, and sell the business to whoever it favors at whatever price it sets. Any company holding factories, stores, or offices in a country where the political relationship with its home government could sour should treat this as the actual playbook, not a hypothetical. If FM Logistic or a company like it sits in your supply chain, find out what happens to your contracts and data the day its Russian entity changes hands.
Sources: Euronews: Russia seizes control over assets of Nestlé, French firms · The Bell: shell company / MVD general appointment

6. North Korea No Longer Needs to Get Hired

North Korea's fake-hire scheme has a new complement: instead of waiting to get a fraudulent employee hired at your company, it is infecting people who have not been hired anywhere yet, on the chance that one of them eventually is.

Four countries moved this week against the support network beneath North Korea's remote-IT-worker scheme, the fraud where operatives get hired at real companies under stolen or forged identities and route their wages to Pyongyang's weapons programs. Argentina opened an investigation into an accused money launderer handling the scheme's earnings and froze some of her assets. Pakistan charged an alleged forger who supplied fraudulent identity documents to North Korean IT workers, and its federal investigators are examining two more people for assisting them. Companies in Vietnam and Laos were sanctioned by the US back in March, after a UN investigation caught them opening bank accounts and laundering earnings for the scheme. None of the people charged this week is North Korean. The whole layer under prosecution is local hired help: document forgers, account openers, money launderers.

A separate North Korean operation, tracked as WaterPlum, skips the hiring step entirely and goes straight for the applicant's device. Its operatives pose as AI and blockchain startups, recruit real job seekers through social media and freelance platforms, then have the candidate download a file during the interview. That file steals cryptocurrency wallet credentials and plants persistent-access tools that wait, in case the victim later lands somewhere worth infiltrating. Between December 2025 and July 2026 it infected at least 30,000 devices across 100 countries and drained roughly 7,000 crypto wallets, hitting mostly web designers, engineers, and crypto specialists, with a heavy concentration in Japan. The FBI, the US Defense Department, Japan's National Police Agency, and police in Australia and Germany issued a joint advisory Friday.

The Takeaway
The old version of this scheme required North Korea to actually get hired at your company. This one does not. WaterPlum infects people speculatively, months or years before any of them might work somewhere worth breaking into, so the access is sitting on a laptop long before you have a reason to look for it. Bring-your-own-device policies make that worse, not better.
Sources: The Record: Nations take action on North Korean IT worker schemes · The Record: North Korean hackers infect thousands of devices, WaterPlum scheme

7. Distance From Land Was Never the Same as Disconnection

A supertanker crossed the Atlantic with hackers reportedly inside its engine room, and officials still won't say why that ship, or nineteen others like it, became a target.

The VL Prosperity is a 1,093-foot Liberian-flagged supertanker capable of carrying 2.3 million barrels of crude oil, managed by South Korea's HMM Ocean Service. On August 7, while the ship passed through the Strait of Gibraltar en route from Egypt to Galveston, Texas, Iran's state Mehr news agency later reported that hackers reached its engine room, slowed the coolant system, pushed the engine speed up, disrupted fuel delivery, and cut communications for roughly 30 hours. A ship in open water still runs on satellite links, remote engine diagnostics, and navigation software that report back to shore, so distance from land does not mean disconnection.

The Coast Guard and FBI have not confirmed Iran's account of what happened, but one day after Mehr's report, a team of Coast Guard cyber specialists and FBI Cyber Action Team members boarded the VL Prosperity and spent four days aboard. The Coast Guard confirmed evidence of malicious cyber activity, without attributing it to Iran. Three days later, on August 24, a second tanker was boarded over a suspected cyberattack of its own: also transiting the Strait of Gibraltar, also headed for the US Gulf Coast, though carrying LNG rather than crude. Nobody in either investigation has said whether the shared route is the actual pattern or a coincidence.

The Coast Guard, FBI, and Department of Homeland Security are now tracking nearly 20 ships worldwide for similar threats and have asked for advance notice before any of them enter a US port. Officials have not explained what put those ships on the list. Similar state-linked maritime incidents have piled up over the past year: a suspected Russian military operation against a container ship in December, and a 2025 attack on Iranian tankers by a hacktivist group called Lab Dookhtegan. One maritime security expert described the goal as creating insecurity, not profit. In early September, an LNG tanker carrying US gas to Italy lost access to some of its own control systems in a separate incident that does not fit the Gibraltar-to-Texas pattern at all, either a second actor or a sign the campaign is wider than one route.

The Takeaway
This is the same lesson every OT operator learns the hard way eventually: distance and isolation feel like security, until you check what is actually connected. A tanker in open water still needs satellite links, remote engine diagnostics, and shore-based monitoring to run, the same systems a factory floor or a water treatment plant depends on to run remotely today. If any equipment in your operation reports data home or takes instructions from off-site, whether it ever leaves your building or crosses an ocean, it likely carries a similar vulnerability.
Sources: SecurityWeek: Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels · Insurance Journal: US Tracking Cyber Threats Against Nearly 20 Ships Worldwide · gCaptain: Another Tanker Suffers Failure as Crew Suspect Cyber Attack

Get this brief in your inbox every Sunday.

No tracking. No spam. One email per week.

Subscribe