Robin’s Newsletter #431

20 September 2026. Volume 9, Issue 38
US authorities board vessels to check for cyber compromise. Google says Gemini kinda did crimes. US Treasury Sec says AI labs should be held liable.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 20th September 2026

  • US boards two vessels, suspected cyber attack victims
  • Google says Gemini compromised orgs, then stopped in testing
  • Treasury Secretary says AI companies should be held liable
  • EC President calls for co-ordinated response to cyber, sabotage
  • Amazon lost data in missile strikes against ME data centres

Interesting stats

$10.5 million stolen by North Korean actors from job seekers across  100 countries, infecting  30,000 devices, and compromising  7,000 cryptocurrency wallets, according to the FBI and Japan’s National Policy Agency 

$1.6 billion lost to fake government and police scams, across  61,000 complaints to the FBI’s Internet Crime Compliant Center (IC3) between January 2025 and July 2026, averaging  $26,000, with  11% alleging a penalty for failing to attend court or missing jury duty.

Five things

  1. US Coast Guard and FBI officials boarded two vessels in the Gulf of Mexico last month to “ensure integrity of the vessel’s operational and information technology systems” after indications that systems on both vessels had been compromised. According to the Coast Guard, which was investigating the attack after the vessel lost communications for 30 hours while passing through the Straight of Gibraltar on the other side of the Atlantic, there was no operational disruption or danger to the crew or the environment. The teams were investigating the source of the attacks and whether they were linked to US-Iran hostilities.

  2. Google has jumped on the oops-we-did-crimes bandwagon, announcing that its Gemini model accessed the internet and broke into three organisations during tests earlier this year. Once again, Irregular conducted the tests, as they did for OpenAI and Anthropic. However, unlike the OpenAI and Anthropic tests, “In all three of these instances, the model stopped,” according to Heather Adkins, Google’s vice-president of security engineering. The incidents occurred in May.

  3. Scott Bessent, US Treasury Secretary, says AI labs should be held “liable for what they build and generate”. The comments came in response to requests from AI leaders at OpenAI, Anthropic, and xAI who have called for a ‘pause’ in development and, less widely reported, called for exceptions for liability for harm caused by their technology.

  4. European Commission President Ursula Von der Leyen has called for a NATO Article 4-style mechanism to convene governments and agree a collective response to cyberattacks and sabotage against the EU. While details on what would happen next or how it would work after being invoked are unclear, I suspect this is most useful as a deterrent against critical infrastructure attacks, which may risk a larger, co-ordinated response from the bloc. NATO’s Article 5 is the collective defence clause, and the EU already has something similar. I’m surprised there’s no equivalent that couldn’t already be used, though perhaps this was intended more as diplomatic posturing.

  5. Amazon says some customer data has been permanently lost in its UAE me-central-1-az2 availability zone, and in all Bahrain me-south-1 availability zones. While availability zones span multiple data centres, AWS was “unable to restore access to the resources and data” following multiple missile strikes on its data centres. This is obviously an extreme event, but a reminder that system redundancy and data backup are different capabilities. 

In brief

And finally

  • Researchers are The Hong Kong University of Science and Technology (HKUST) say they have found a way to listen in on the analogue signals in headphones from up to 30m away. The ‘InjectEave’ technique is an electromagnetic side channel attack that relies on transmission of a 0-9MHz signal and other receiver equipment to modulate and capture the signal. The paper (PDF) says it has been successfully tested against a range of devices including wired and wireless headphones from Sony and Apple, VOIP telephones, and smart devices.

  • ShinyHunters have breached the Clop ransomware group’s data leak site, apparently stealing data and private keys. Such terrible news. I hope they spend a long time fighting each other.

Robin
  Critical National Infrastructure (CNI) Artificial Intelligence (AI) North Korea Liability Redundancy Backup Maritime Satellite