Three Things You Should Know: September 22, 2026

Concentric is monitoring the increasing energy and aviation risk across the Arabian Peninsula, after Houthi forces struck a fuel depot at Riyadh’s King Khalid International Airport days after completing their takeover of the Bab al-Mandab strait, with Iran’s blockade of Hormuz still in place. We are also tracking infrastructure sabotage in Western Europe, including coordinated attacks on the Dutch rail network on Budget Day and a suspected sabotage-linked derailment in Normandy. Finally, we are assessing the impersonation risk to executives after an identity verification firm confirmed intruders spent five months inside its systems and took passport and license scans belonging to an estimated 13 to 15 million people.

Houthi Strike on Riyadh Extends Energy and Aviation Risk Across the Arabian Peninsula.
Houthi forces struck Riyadh overnight into September 19, igniting a fuel storage depot at King Khalid International Airport and disrupting operations at one of the region’s busiest aviation hubs. The Saudi-led coalition confirmed an attempted ballistic missile strike on the capital, which it said was intercepted and the Saudi Civil Defense pushed hostile aerial threat alerts to mobile devices in Riyadh and Al-Kharj. The strike follows the Houthis’ rapid coastal offensive when they seized the strategic Red Sea islands and sealed control of the Yemeni side of the Bab al-Mandab strait, with the capture of Mayyun Island placing around a third of global chokepoint traffic under pressure alongside Iran’s Hormuz blockade. Reuters analysis of satellite imagery subsequently identified damage at three pumping stations, and Aramco officials told at least two European refining customers they will receive no crude under term contracts in October. Brent reached nearly $110 early last and JPMorgan estimates Middle East oil flows averaged around 17 million barrels a day over the past ten days, roughly six million below the 2025 average. US diesel is at a record average of $6.43 a gallon and regular petrol at $4.47, up $1.53 since February, while households reliant on heating oil face winter bills more than 31 percent higher than last year. We assess Riyadh remains a target of Houthi forces and further disruption at Saudi aviation and energy nodes is likely in the near term. Organizations with Gulf exposure should re-confirm routings and ground handling for Saudi hubs, brief travelers on civil defense alerting and shelter procedures, revisit fuel and freight assumptions, and map supplier dependence on Red Sea and Gulf transits.

Coordinated Rail Sabotage Halts Dutch Network and Exposes Continuity Gaps.
Coordinated sabotage halted rail traffic across central and eastern Netherlands on September 15, demonstrating a national network can be disabled using basic materials and no specialist access. ProRail classified the incident as deliberate sabotage after finding pipes attached to the rails at more than 30 locations, which caused signaling to read affected sections as occupied and halted all trains through them. A train struck one section at Steenwijk without injuries, and international services to Germany were also seriously impacted. Police and the Dutch Intelligence Service (AIVD) are investigating and no one has claimed responsibility for this incident. Farmers protesting the government budget set hay bales and tires on fire beside motorways the same day, and seven people were arrested near Breukelen, though authorities have not established a link between the two sets of incidents. Separately, a Rouen to Caen regional train derailed four days earlier at Cléon in Normandy, injuring 44, including one person in critical condition, with investigators treating a rail fragment found on the track as the main line of inquiry. French authorities have not confirmed sabotage and have not established a link to the Dutch incident. We assess the significance of the Dutch incident lies in what it demonstrated as a national rail network was halted for a day using low-cost materials, applied to unattended track, by actors who remain unidentified. We suggest clients with Dutch, Belgian, German and French operations should treat rail as a point of failure in continuity planning and confirm crisis communications reach staff whose commute fails without warning.

Identity Verification Firm Confirms Five-Month Breach of Passport and License Scans.
IDScan.net told the Illinois Attorney General on September 17 intruders held access to its systems from April 1 to September 2 and stole identity documents belonging to an estimated 13 to 15 million people. It is the company’s first estimate of scale. The stolen data may include full names with dates of birth and driver’s license, passport and other government-issued identification numbers. IDScan’s customers include car rental firms, retailers, logistics companies and hospitality venues, all of which scan IDs at counters and check-in kiosks. Staff and executives enter the dataset through ordinary transactions. For example, the U.S. Secretary of War Pete Hegseth’s driving license was advertised for $100. Nexus went dark on September 2 and the Federal Bureau of Investigation opened an investigation. We assess the main risk of this breach is likely impersonation, rather than credit fraud because a license or passport stays valid for years and document images also clear checks that a stolen ID number would fail, including remote onboarding, service desk verification and physical access control. If executives are concerned they might be impacted by the breach, we recommend requesting  a call back on a known number before acting on any account change, payment instruction or credential reset supported by a document image. We also suggest extending vendor due diligence to any third party that scans and stores identity documents, and asking how long they keep these items.

Related Posts