Cybersecurity

Insurance Industry Scrambles for Tech & AI Talent

Whether driven by retirements or re-configuration, the insurance industry is scrambling for tech talent.

This article appears in the July/August issue of Global Finance Magazine.

Caught between a wave of retirements and a weak talent pipeline short on tech-savvy candidates, the insurance industry faces a talent shortage that could affect its ability to address cyber and other emerging risks.

“Demand is rising sharply for fluency in analytics, AI, as well as in cyber risk. These are all capabilities that are either new or that the traditional sources of talent haven’t produced at scale,” says Peter Miller, president and CEO of The Institutes, a risk management and insurance education provider. 

In 2014, to help expand the talent pool, a group of risk management and insurance companies, nonprofits, and educational institutions, led by The Institutes, created MyPath, a one-stop resource for job seekers that outlines the benefits of, and pathways to, insurance careers.

The initiative remains timely because, in a November 2024 Institutes report, 66% of insurance professionals in the property and casualty sector surveyed identified the loss of institutional knowledge as the retirement wave’s greatest impact: “The result is both a talent shortage and a knowledge-transfer risk.” That means organizations must find ways to “preserve institutional expertise that took decades to build” while developing new skills.

Other Industry Observers Agree

“There is a dual-sided talent crisis,” says Margaret Milkint, global insurance practice leader at DSG Global, an executive search firm. “Organizations are losing experienced professionals faster than they can be replaced while simultaneously racing to build leadership capacity around capabilities that barely existed a decade ago.”

The talent crunch is rippling beyond primary insurers to encompass reinsurance carriers, brokerages, and risk management firms, she says. “Artificial intelligence is creating an entirely new category of roles spanning enablement, governance, ethics, and cultural integration that require skill sets the traditional insurance pipeline was never built to produce.”

The shortage of talent with tech and AI capabilities has become one of the industry’s most critical gaps as roles across underwriting, claims, and risk management become more data-driven, says Victor Harris, vice president at financial services recruiter Selby Jennings. “The shortage is slowing the pace at which many organizations can fully adopt and scale their AI strategies,” he warns.

Worsening Insurance Talent Squeeze

While they agree that AI is increasing demand for certain roles, experts at Aon observe that AI and automation are reducing demand in some entry-level and operations slots, particularly in finance and reporting. 

“There is a risk of mischaracterizing the issue as a blanket shortage,” says Louisa Blain, head of insurance for human capital at Aon. “The reality is more nuanced, and linked to where the industry wants to grow versus the skills it currently has versus requirements for the future. This is less about replacement and more about reconfiguration of the workforce.”

Louisa Blain, Aon
Louisa Blain, Aon: This talent shortage is less about replacement and more about reconfiguration of the workforce.

Yet, the talent constraints could limit industry growth in specialist and emerging risk areas, argues Jeff Reider, head of Aon’s benchmarking, strategy and technology group. The Institutes’ Miller sees the shortage coming in cyber, complex liability, multinational program structuring, and cross-jurisdictional claims coverage. 

“Knowledge lost to retirement can have meaningful downstream effects on compliance and strategy,” he says. “For any multinational that depends on its risk transfer partners to keep pace with growing exposure complexity, this is a material consideration.”

The infusion of capital and the emergence of new carriers and managing general agents in specialty lines have made the talent squeeze more pronounced over the last five years, says Tony Chimera, chief administrative officer at carrier Westfield Specialty. 

“That has pulled talent out of the pool used by insurance carriers and brokers,” he adds, noting the talent squeeze has been building for two decades. “You do have an aging workforce. Some people are working longer, but you have a 55- to 65-year-old workforce that is probably not going to be there in the next five years.”

In addition, insurers are competing with the banking and technology sectors, which many younger professionals are turning to for more attractive careers with greater compensation. Yet, the actual compensation for some banking sector jobs, when salaries are integrated with a lack of work/life balance, can be much less desirable than insurance roles, Chimera points out: “Insurance is a great industry where you can earn a lot. And you can have a life.”

But Harris notes that many insurers’ locations in midsize cities can dissuade younger professionals intent on living in larger, more alluring metropolises. That leaves the industry with a limited pool of specialized talent.

Technical Fluency Isn’t Everything

How, then, is the industry to attract new talent? 

The technology industry could be one source, Chimera says. But candidates must accompany the tech skills needed for roles in data analytics, AI, and cybersecurity with knowledge of the complex insurance business. 

“Technical fluency alone doesn’t translate directly into effectiveness in risk management and insurance,” says Miller, adding that regulatory knowledge, coverage mechanics, and underwriting judgment take time to develop. “The most successful transitions involve strong technical capabilities combined with a genuine curiosity to develop insurance-specific expertise.”

While agreeing that the talent shortage has been building for years, Milkint notes that there is no clear consensus on when, or whether, it will peak. “Closing this gap,” she says, “will require the entire industry to go on the offensive and actively dismantle outdated stereotypes, confront long-standing biases, and make a compelling, unified case that insurance is not just keeping pace with the future, but helping to shape it.”

To attract more students from outside the traditional insurance and risk management programs, the industry must expand students’ awareness of career opportunities “beginning well before students reach their junior and senior years of college,” says Grace Grant, executive director at Gamma Iota Sigma. The collegiate society represents more than 7,000 students interested in careers in insurance, risk management, and actuarial science across 177 colleges and universities.

“Many students simply are not exposed to the breadth of careers available in the industry,” Grant says, adding that employers should highlight their innovation, technological sophistication, purpose-driven work, career stability, and advancement opportunities. “Students are highly motivated by careers where they can make a meaningful impact, and insurance is fundamentally about helping individuals, businesses, and communities recover from loss and manage uncertainty.”  

Paula L. Green is a contributing writer based in New York City.

Source link

Open AI says its AI model “went rogue”: What do we know? | Cybersecurity News

OpenAI has revealed that one of its artificial intelligence models independently stole login credentials and hacked into another technology company’s system, in what is widely seen as one of the first known incidents of AI systems acting autonomously.

“We had a significant security incident during evaluation of our models,” CEO Sam Altman posted on X on Tuesday.

Recommended Stories

list of 4 itemsend of list

The incident comes as calls mount from technology rights advocates for stricter guardrails on rapidly evolving AI systems.

They have grown so powerful in a short span of time that alarming phenomena such as deepfakes and sophisticated cyberscams are becoming the norm.

Earlier this year, a number of software engineers quit their jobs at top companies such as Anthropic and AI in protest against how the technologies are being built.

“AI is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in a lengthy statement on Tuesday that detailed the latest incident.

“The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

Here’s what we know about the breach:

Sam Altman, cofounder and CEO of OpenAI, testifies before a Senate committee hearing in Washington, May 8, 2025
Sam Altman, cofounder and CEO of OpenAI, testifies before a Senate committee hearing in Washington, May 8, 2025 [Jose Luis Magana/AP]

What has happened?

OpenAI said two of its models found their way out of an isolated, no-internet access environment – or a sandbox – and hacked into the systems of tech company Hugging Face on their own.

The models involved are the latest GPT-5.6 Sol model and an unreleased model the company said is “even more capable,” than its latest version.

Hugging Face hosts openly sourced AI models and resources. The two OpenAI agents discovered vulnerabilities in Hugging Face’s servers and proceeded to steal login details and then hack into the company’s systems.

The incident occurred during an OpenAI internal testing session designed to assess the models’ cybersecurity capabilities. OpenAI had removed standard safety measures for the test.

Both sought to cheat their way through a problem during the test, OpenAI said. They went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation”.

OpenAI’s security team detected the unusual activity internally, but details of the breach came to light following a joint investigation by both companies.

What has Hugging Face said?

Hugging Face disclosed last Thursday that its servers were hacked by an unknown but sophisticated agent acting on its own. The company discovered the breach through its own AI-assisted detection.

“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system,” the company said.

Following OpenAI’s disclosure that its models were involved in the breach, both sides conducted an ongoing joint investigation this week.

 

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!” CEO Clement Delangue posted on X on Tuesday.

Hugging Face’s staff “strongly believe there was no malicious intent on their part,” Delangue added, referring to OpenAI.

Why does this matter?

Cybersecurity experts have previously sounded the alarm over the potential, extreme capabilities of AI systems and the dangers they pose.

But until now, there have been few real-life cases proving those concerns like this one.

Many warn that incidents like these could become commonplace and that AI systems pose a threat to financial, security and other sensitive data systems.

OpenAI revealed in a separate incident earlier this week that the unreleased, more powerful model had escaped an isolated environment during another test.

Anthropic, OpenAI’s rival, had similar issues with its most powerful agent to date, the Claude Mythos Preview model.

During a stress test of an early version, the model found its way out of a sandbox, gained internet access and emailed the supervising researcher that it had escaped and then wiped evidence of its activity. Anthropic halted a planned public release of the model afterwards.

In April, the US Federal Reserve and the Treasury Department convened a meeting with bank CEOs where officials warned about the cybersecurity risks posed by Mythos. Canada’s federal banking regulator has also warned financial institutions about the model’s capabilities.

The OpenAI breach also appears to make the case for companies like Hugging Face, which rely on open source systems, as opposed to more secretive AI development platforms like OpenAI.

“This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret,” Hugging Face’s Delangue was quoted as saying in OpenAI’s statement.

“It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere,” he added.

Source link

‘Unprecedented’: OpenAI says AI models autonomously hacked another company | Cybersecurity News

ChatGPT maker says an autonomous agent escaped a controlled test and accessed AI firm Hugging Face’s servers.

ChatGPT creator OpenAI has said that two of its most advanced artificial intelligence models broke out of a controlled test and hacked another AI company.

OpenAI said on Tuesday that the “unprecedented cyber incident” took place during an internal exercise meant to test its models’ cyber capabilities.

Recommended Stories

list of 3 itemsend of list

Instead, an autonomous agent powered by the AI models – the newly released GPT 5.6 Sol and an unreleased “even more capable” model – escaped the test environment and reached the open internet. It then used stolen login details and found a previously unknown security flaw to access Hugging Face servers, the company said.

OpenAI claims that the hack represented the agent going to “extreme lengths” to retrieve information that would help satisfy the testing goals.

Hugging Face cofounder Clement Delangue said the company had suspected that a frontier lab was behind the attack, and that he believed there was no malicious intent on OpenAI’s part.

“It’s quite mind-blowing that all of this happened autonomously!” he wrote, adding that it “might be the first incident of its kind”.

Greg Casar, a Democratic member of the United States House of Representatives from Texas, called the incident “alarming”.

“AI is developing extremely fast with no real regulations to keep us safe,” he said, calling for mandatory independent safety testing, mandatory disclosure of security incidents, and international cooperation.

The disclosure comes weeks after US President Donald Trump signed an executive order creating a framework to vet the national security risks of the most advanced AI systems before their public release.

Experts have repeatedly sounded the alarm over AI-enabled cyberattacks and models slipping beyond human control. Last month, AI developer Anthropic urged the industry to pause development of its most powerful systems.

Source link

Meta backtracks on AI-image feature for Instagram due to privacy backlash | Cybersecurity News

NewsFeed

Meta has rolled back its ‘Muse Image’ AI feature after widespread backlash over privacy and consent. The tool allowed users to generate AI images of people by simply ‘@ mentioning’ public Instagram accounts. The negative reaction was swift and global – forcing Meta to say it ‘missed the mark’.

Source link

Australia to double fines on Big Tech as children bypass social media ban | Social Media News

Canberra says tech platforms are still letting too many children bypass its under-16 social media ban.

Australia says it will double fines on social media companies that fail to keep children off their platforms, accusing Big Tech of dodging the spirit of its under-16 ban.

The government said on Saturday that new legislation would raise the maximum penalty for systemic breaches from 49.5 million to 99 million Australian dollars ($31m to $68m) and give the eSafety Commissioner stronger powers to force platforms to comply.

Recommended Stories

list of 3 itemsend of list

The regulator is investigating possible breaches by Facebook, Instagram, Snapchat, TikTok and YouTube.

“It’s clear Big Tech are not doing enough to comply with the law – there are still too many children on social media,” Prime Minister Anthony Albanese said.

“These changes reflect the seriousness with which we take any failure by social media companies to comply.”

The ban, which came into force on December 10, made Australia a global test case for countries trying to curb children’s access to social media. The United Kingdom, Indonesia, the United Arab Emirates and New Zealand are among those watching or considering similar restrictions.

But children have continued to evade the rules by using accounts registered to older people, creating fake profiles or logging in through private browsers.

A peer-reviewed evaluation published this month in the British Medical Journal found “insufficient evidence” that the ban had sharply reduced social media use among young people. Researchers surveyed more than 400 children before the measure took effect and again three months later, finding “substantial circumvention” of the rules.

The government says more than five million accounts held by under-16s have been blocked, but Communications Minister Anika Wells said platforms were still falling short.

“Based on the regular updates I receive from the eSafety Commissioner, it is clear to me that social media platforms are adopting tricks straight out of the Big Tech playbook and doing the bare minimum to get by,” Wells said.

“Social media platforms are some of the richest and most powerful companies in the world, and we’re serious about holding them to account,” she added.

The new powers would allow the eSafety Commissioner to demand documents and evidence from platforms, age-checking companies and app stores.

Platforms must show they have taken “reasonable steps” to keep under-16s out. Some use artificial intelligence to estimate ages, while users can also verify their age with a government ID.

Source link

Securing Critical Infrastructure Against Early-Stage Ransomware: Proactive Steps for Prevention

Critical infrastructure, such as water utilities, energy grids, healthcare systems, manufacturing plants, education platforms, and transport networks, have become primary targets of ransomware groups. In late April and early May 2026, for instance, Shinyhunters, a hacking group, breached Instructure, an education platform used by K-12 schools and universities across the US, and claimed for ransom. In the report published on CNN, the hacker group said it had breached 275 million personal data and had access to billions of private messages, an action that has affected thousands of schools, causing learning disruptions. Cybercriminals target critical infrastructure because downtime means communities don’t get access to essential services. So, operators or service providers have no option but to pay ransom to restore services quickly. Security gaps also influence the growth of these attacks. Too often, organizations focus on recovery efforts and ransomware encryption instead of prevention. This post highlights ways to prevent ransomware at its early stages, including the use of zero trust architecture and AI.

Promote Cybersecurity Awareness

Ransomware incidents start with malicious malware being injected into tech infrastructure. It then encrypts data and systems, restricting organizations any access to their operations until a ransom is paid. For these attacks to be successful, however, threat actors rely on social engineering attacks like spoofing and phishing, which target employees. An attacker will send a phishing email, impersonating an executive or trusted source like a bank to trick the victim into sharing credentials. Today’s spam emails, especially those generated by AI, are flawless, meaning staff can easily open and click on malware links without suspecting any threat. So, it’s crucial that employees receive adequate training on how to spot and respond to phishing texts or emails and malicious links.

Workers should also know how to generate hard-to-hack passwords. Weak passwords or using the same password for multiple accounts creates an entry point for ransomware. Encourage the use of password phrases, which are a string of unrelated, random words, symbols and numbers. For example, a password like purplegiraffesingstomorrow@17 prevents brute-force logins because a hacker will have a hard time guessing. Alongside passphrases, emphasize the importance of multi-factor authentication, where staff use two or multiple authentication methods to gain permission to accounts. 

Enhance Threat Detection and Monitoring Systems

Detecting ransomware at its early stages helps prevent full encryption of sensitive data and infrastructure. And it entails identifying subtle behaviors of the threat, such as lateral movement across networks and devices, data exfiltration, and privilege escalation. Look out for unusual login or data access, increases in CPU usage, and abnormal network traffic to command-control servers. Modern attacks powered by AI and machine learning bypass legacy security systems by using legit utilities like PowerShell scripts and MimiKatz. So, check if there are attempts by script-based systems like PowerShell to inject suspicious code into running processes. Also, inspect if endpoints and firewalls are still running. Attackers often switch them off or configure settings without authorization to create a weak point for malware injection. 

Note: lateral movement and zero-day variants aren’t always easy to spot. You need to integrate multiple security tools to detect and mitigate attacks. Use endpoint detection and response tools to catch harmful scripts and abnormal file access before all your data is encrypted. Take advantage of AI-assisted behavioral analytics to learn data access patterns, set a baseline for normal user behavior, and send alerts when there’s unusual or irregular file access patterns to protect against infostealers. Since infostealers act as the initial access for attack vectors, stopping them eliminates the entire kill chain. You can also reinforce your security measures by working with a 24/7 AI-centric SOC. These security experts don’t just distinguish legitimate logins from malware injections. They isolate the host to stop further compromise.

Network Segmentation and Zero Trust Framework

The goal of these two security measures is to limit a hacker’s ability to infect an entire network. Segmenting your networks entails dividing your networks into smaller, isolated sub-networks that make it difficult for cybercriminals to navigate critical network infrastructure. In a situation where a device is compromised, segmentation locks the attack within the specific zone, ensuring it doesn’t access databases or other sub-networks. What does zero trust entail and how does it mitigate ransomware? This tactic works on one strict principle: ‘never trust, always verify’. It doesn’t matter if you’re an authorized user or the devices you’re using are inside the organization. With zero trust in place, every access request is authenticated continuously. Also, users are granted permission to data and tools based on their roles to minimize privilege. Even if an attacker stole credentials, they would be limited to access systems. When combined, zero trust architecture and network segmentation strengthen an organization’s cyber safety strategies.

Hackers know that when they infect essential infrastructure with ransomware, victims will act fast to settle the ransom required to get encryption keys. But service providers shouldn’t wait until an attack has occurred to secure infrastructures. Prevention is the most effective strategy, and it revolves around simple hacks like educating workers about common threats and using strong pass phrases alongside MFA. By detecting threats, implementing zero trust, and network segmentation, organizations can minimize ransomware-related risks.

Source link

Meta to take legal action against Israeli spyware company NSO | Cybersecurity News

WhatsApp disrupted phishing attempts linked to NSO, blacklisted by the US for security concerns.

Meta has said it is ⁠filing a federal US ⁠court contempt order against Israeli spyware firm NSO Group for violating a permanent injunction that barred it from ever ⁠targeting WhatsApp and its users.

The company said on Monday that its WhatsApp messaging service disrupted new spear phishing attempts linked to NSO, an ⁠entity blacklisted by the United States government for engaging in activities that are contrary to national security or foreign policy interests.

Recommended Stories

list of 3 itemsend of list

These attempts were similar to previous “1-click phishing campaigns”, aimed to trick users into clicking ‌malicious links and direct them to external websites, Meta said in a blogpost.

A “1-click” is a type of cyberattack where a single click on a malicious link or attachment is sufficient to compromise a victim’s device or account, without requiring them to enter their credentials.

Meta said WhatsApp took down test accounts ⁠and groups created by NSO on its platform. ⁠NSO did not immediately respond to a Reuters request for comment.

Last year, a US court ordered NSO to stop targeting Meta’s WhatsApp, a development the spyware ⁠company warned could put it out of business.

While the ruling significantly reduced the punitive damages NSO ⁠owed Meta to $4m from an ⁠initial $167m, the injunction itself was seen as a substantial challenge for the company, which faces ongoing accusations of enabling human rights abuses through its Pegasus hacking tool.

Meta ‌said on Monday that last month it was joined by 12 prominent civil rights organisations, a coalition of security researchers, privacy advocates ‌and ‌digital rights experts, who filed their amicus briefs to fight NSO’s appeal against the permanent injunction.

Source link

Trump signs an executive order to vet top AI models for national security risks

President Trump signed an executive order on artificial intelligence Tuesday, less than two weeks after postponing a White House ceremony over his concerns that a similar policy could dull America’s edge on AI technology.

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. The government will be able to work with trusted partners “that will have early access to covered frontier models to promote secure innovation and strengthen the cybersecurity of critical infrastructure,” the order says.

It was not immediately clear to what extent the order differed from the one he declined to sign on May 21.

Trump canceled an Oval Office event with tech industry executives last month because he did not like what he saw in the earlier version of the order’s text. “We’re leading China, we’re leading everybody, and I don’t want to do anything that’s going to get in the way of that lead,” Trump told reporters at the time.

That directive was characterized as a voluntary collaboration with participating U.S.-based tech companies, including Anthropic, OpenAI and Google.

O’Brien writes for the Associated Press.

Source link

Beware of Financial Scammers Wielding Deepfake Tech

Deepfake fraud is becoming a persistent, multiyear corporate risk as synthetic voices circulate undetected.

Deepfake-enabled fraud, which began as novel technical exploits, is now a persistent operational risk with a multi-year shelf life within the corporate ecosystem. According to deepfake-detection provider Resemble.AI, deepfakes typically remain in circulation for three-and-a-half years.

Resemble.AI’s 2025 Deepfake Threat Report, published in March, references an incident in which a voice clone of a German energy company CEO remained in circulation for nearly six years, although it resulted in only a €243,000 loss in 2019.

Determining losses from such attacks is difficult; for the 41 documented incidents last year cited by the research, only $74.9 million in verified losses were reported, with a median per-incident loss of $243,000. However, the authors noted that 71% of victims did not report financial losses, suggesting a higher volume of hidden liabilities.

“What makes them so effective is that they enable both real-time impersonation and the creation of synthetic identities stitched together from real and fake data,” said Dominic Forrest, CTO of biometric security vendor Iproov. “These are extremely difficult to detect, and once trusted, they can be used to bypass controls and commit fraud.”

AI Arms Race

Detecting deepfakes is a growing concern; the authors of the Resemble.AI report estimate that deepfake-based fraud attacks on corporations reached 8.5 billion potential incidents, ranging from audio impersonations of executives to doctored or fake images. The most common targets, Forrest noted, are on account openings, payment authorization, credential reset, and high-value transactions.

Telling a deepfake from the genuine article has become an AI-on-AI battle, experts warn.

The generative AI models producing deepfakes improve continuously via scaling and data, while deepfake detectors rely on signals like artifacts and inconsistencies, which disappear as models improve, said Siwei Lyu, professor of Computer Science and Engineering and director of the Institute for AI and Data Science at the State University of New York at Buffalo.

“In practice, detectors lag by about six to 18 months on specific modalities,” he said. “But more importantly, they are chasing a moving target whose failure modes are actively being optimized away.”

Forrest suggests that firms move their identity verification from single checks to a multi-layered approach: “You need to confirm that a real person is physically present, not a deepfake, while also analyzing the digital environment for signs of compromise. No signal should be trusted in isolation.”

This article first appeared in the May edition of Global Finance Magazine.

Source link

What is the UAE’s Barakah nuclear plant, nearly hit by a drone? | Conflict News

A drone attack that caused a fire close to the Barakah Nuclear Energy Plant in the United Arab Emirates has raised further concerns about nuclear security and military escalation in the Gulf as discussions of peace between Iran and the United States hang in the balance.

Barakah was the first nuclear power station to be built on the Arabian Peninsula. Here is what we know about it:

What is the Barakah Nuclear Energy Plant?

Barakah is a nuclear energy plant located in Al Dhafra, the largest municipal region of the emirate of Abu Dhabi. It is the UAE’s only nuclear power plant.

Construction of the plant began in 2012, and its first reactor became commercially operational in 2021.

The plant is located close to the border with Saudi Arabia, about 225km (140 miles) west of the UAE’s capital city, Abu Dhabi.

The facility features four pressurised water reactors, the most common type of nuclear power reactor. The model used here is the advanced power reactor 1400, a pressurised water reactor design developed in South Korea. Each reactor of this type has the capacity to produce 1,400 megawatts (MW), which is enough to power roughly 1 million homes.

According to the Emirates Nuclear Energy Corporation (ENEC), the plant’s reactors produce 40 terawatt-hours (TWh) each year, which is equivalent to about 25 percent of the UAE’s electricity needs. The website for the London-based World Nuclear Association also confirmed that Barakah, when fully operational, meets 25 percent of the UAE’s electricity needs.

According to a September report by the Abu Dhabi media office, Barakah had produced 40TWh of clean energy over “the past 12 months”.

Since nuclear power plants produce a lower amount of carbon dioxide emissions than conventional power plants, the ENEC said Barakah saves up to 22.4 million tonnes of carbon emissions each year, equivalent to removing 4.8 million cars from the roads.

What happened in the attack on Sunday, and how has the UAE responded?

Authorities in Abu Dhabi said a single drone strike caused a blaze to break out at an electrical generator outside the Barakah plant’s inner perimeter in the Al Dhafra region on Sunday. No injuries were reported, and officials said radiation levels remained normal.

The UAE’s nuclear regulator said operations at the Barakah facility had not been affected. “All units are operating as normal,” it said in a social media post.

In a statement, the UAE’s Ministry of Defence said two more drones had been “successfully” intercepted and the drones had been launched from the “western border”. It did not give more details.

The UAE’s Ministry of Foreign Affairs posted a statement on X on Sunday saying the country condemned “the unprovoked terrorist attack” in “the strongest terms”.

The statement added: “The UAE emphasised that it will not tolerate any threat to its security and sovereignty under any circumstances, and that it reserves its full, sovereign, legitimate, diplomatic, and military rights to respond to any threats, allegations, or hostilities in a manner that ensures the protection of its sovereignty, national security, territorial integrity, and the safety of its citizens, residents, and visitors, in accordance with international law.”

There was no immediate claim of responsibility, and the statements by the ministries did not publicly blame any country.

But Anwar Gargash, an adviser to the UAE’s president, wrote in an X post on Sunday: “The terrorist targeting of the Barakah clean nuclear power plant, whether carried out by the principal perpetrator or through one of its agents, represents a dangerous escalation and a dark scene that violates all international laws and norms, in criminal disregard for the lives of civilians in the UAE and its surroundings.”

Gargash’s post appeared to blame Iran and its proxy network of allied armed groups in the region, which Tehran calls the “axis of resistance”.

The launch point of the drones remained unclear, but on Sunday, Saudi Arabia also reported it had intercepted three drones that had been launched from Iraq, where some Iran-allied groups operate. If Iranian Shahed-136 drones, which have an estimated range of 2,000km to 2,500km (1,240 to 1,550 miles), were fired from Iraqi territory, both Saudi Arabia and the UAE would fall well within their reach.

Other reactions

Neighbouring Gulf states Saudi Arabia and Qatar condemned the attack on the Barakah plant.

The Ministry of Foreign Affairs of Kuwait also issued a statement denouncing the attack, which it called “heinous”.

The Indian Ministry of External Affairs condemned the attack, calling it “unacceptable”, saying it represented “a dangerous escalation” and urging a return to diplomacy.

Has Iran responded to the incident?

Iran has not claimed responsibility for the drone attacks, and there has been no public statement from Iran about the incident at Barakah.

However, in the aftermath of the drone attacks, United States President Donald Trump wrote in a Truth Social post: “For Iran, the Clock is Ticking, and they better get moving, FAST, or there won’t be anything left of them. TIME IS OF THE ESSENCE!”

Iranian Ministry of Defence spokesperson Reza Talaei-Nik said on Sunday that the military is “fully prepared” to confront any new aggression from the US and Israel.

Iran has previously warned that countries where US military assets are deployed or Israeli-linked interests are located are viewed as legitimate targets.

Iran has also accused the UAE of strengthening ties with Israel while reports have emerged that Israeli Prime Minister Benjamin Netanyahu made a “secret” visit to the Gulf state during the US-Israel war on Iran. The UAE has denied this.

US Ambassador to Israel Mike Huckabee also said last week that Israel had deployed Iron Dome air defence systems and personnel to the UAE to help defend against possible Iranian attacks.

What has the IAEA said?

The International Atomic Energy Agency (IAEA), the global nuclear watchdog, said Sunday’s incident in the UAE had forced one reactor to rely temporarily on emergency diesel generators.

IAEA chief Rafael Grossi expressed “grave concern” and warned that military activity threatening nuclear facilities was “unacceptable”.

How serious could a strike on a nuclear facility be?

Attacks on nuclear power plants are especially worrying because they can risk damaging critical safety systems or reactors, which could release radioactive material into the atmosphere, not only over the country targeted but also across neighbouring states. Radiological material, specifically the hazardous isotope Caesium-137, could be released into the atmosphere.

The release of radioactive material could result in environmental contamination and poses major risks to public health. Water, if contaminated, becomes undrinkable while farmland and fisheries could become unsafe for decades, depending on the isotope released.

Short-term, acute exposure to radioactivity can cause burns and acute radiation sickness, which can be life-threatening.

Prolonged exposure, even to smaller doses, can increase the risk of illnesses such as cancer, especially thyroid cancer and leukaemia. Children and pregnant women are especially vulnerable.

Over the course of the US-Israel war on Iran, energy infrastructure has become a target.

Iran’s only functioning nuclear plant, the Bushehr power plant, has come under repeated attacks in the war. There are fears that damage at Bushehr could contaminate water across the entire Gulf region, most of which lacks groundwater and relies heavily on the desalination of seawater. Desalination plants are not specifically built to filter radioactive material, and not all plants currently are fitted with the technologies required to do so.

Source link

Social media becomes a ‘goldmine’ for fraudsters in Jordan | Crime News

Fake online advertisements and social media groups are luring people in Jordan with promises of “quick profits” from cheap gold with sellers disappearing once funds have been transferred or customers defrauded with counterfeit and substandard metals, Jordanians tell Al Jazeera.

Mohammed Nassar said he was quoted a price for gold lower than local market rates due to an “online store” claiming it was exempt from manufacturing fees, government licensing costs or shop rents.

The Jordanian shopper transferred the money to secure what he thought was a bargain before the website disappeared and Nassar realised he had become the victim of a scam.

In another case, a young woman named Tala Al-Habashneh told Al Jazeera that she bought gold through a social media platform after agreeing with the seller and transferring the promised amount.

On closer examination of the product, she found that her gold was counterfeit, mixed with other metals and lacking any official stamps or invoices to prove its origin or carat.

Tala immediately filed a complaint with the Cybercrime Directorate of Jordan’s Public Security Directorate. The case is pending.

Government monitoring

Wafaa Al-Momani, assistant director general for Regulatory Affairs and director of the Jewelry Directorate at the Jordan Standards and Metrology Organisation (JSMO), told Al Jazeera that the institution is the only entity in the kingdom responsible for monitoring precious metal jewellery – such as gold, silver and platinum – and overseeing jewellery trading.

All imported jewellery is examined and stamped by the JSMO before being released onto the market, she said, while local workshops are also required to submit jewellery for inspection and verification before it can be sold.

FILE PHOTO: A woman picks a gold earring at a jewellery shop in the old quarters of Delhi, India, May 24, 2023. REUTERS/Anushree Fadnavis/File Photo
Gold is an important commodity for savings and investment in many parts of Asia [File: Anushree Fadnavis/Reuters]

Al-Momani said her organisation has received some complaints about companies, websites and social media groups engaged in fraud by “promoting the buying and selling of gold, especially broken gold [used or damaged], through unlicensed individuals”.

The JSMO is monitoring sellers engaged in fraud in coordination with security authorities to prevent jewellery from being sold outside licensed shops.

Al-Momani said the JSMO is tightening oversight of gold shops and sellers in the kingdom and said any store found selling unstamped jewellery or violating legal standards will face legal penalties but also warned Jordanians that buying gold through unofficial channels “does not guarantee that the jewellery conforms to legal standards or carats”.

Adornment and treasure

Rabhi Allan, the head of the Jordanian Association of Jewelry and Goldsmiths, explained that gold remains a traditional means of saving and investment for Jordanians as well as an accessory, quoting the popular saying: “Gold is an adornment and a treasure.”

However, he described the sale of gold through social media as “alien to Jordanian society” and stressed that transactions of this “cash commodity” should only take place via official shops with invoices clearly stating the weight, carat and labour costs of the product.

He said the association had filed complaints with the Cybercrime Directorate against unlicensed and anonymous sites, noting that these pages “appear and disappear without warning”, a situation that leaves victims without the ability to secure their consumer rights.

The association has documented numerous complaints and court cases resulting from gold sales conducted through social media platforms that often use edited or fabricated images and fake offers to attract buyers.

Others offer gold at prices significantly below market value to lure buyers, but the product sold is often counterfeit, nonexistent or contains far less of the precious metal than advertised.

He urged citizens to buy gold only via licensed and accredited shops that display official prices and issue proper invoices to protect buyers’ rights.

While questions have been raised about whether some gold sales conducted through social media could be linked to illegal activities, Allan said the cases monitored so far appear to be “individual incidents that do not amount to money laundering”.

Security warning

The Cybercrime Unit of the Public Security Directorate also warned citizens against buying gold through social media advertisements and confirmed that the body has received multiple complaints of fraud linked to the trade.

Colonel Amer Al-Sartawi, Public Security Directorate spokesperson, told Al Jazeera that the grievances ranged from cases where money was wired to fraudsters who subsequently disappeared without delivering the promised gold to incidents in which buyers received counterfeit pieces made from other less valuable metals, such as copper or iron.

Al-Sartawi urged citizens not to deal with such pages and to buy gold exclusively from licensed and accredited shops.

Source link