EU Welcomes Turkish Ship's Return to Port from near Cyprus

A Turkish Petroleum (TPAO) engineer poses on the helipad of the Turkish drilling vessel Yavuz in the Eastern Mediterranean off Cyprus, Aug. 6, 2019. (Reuters)
A Turkish Petroleum (TPAO) engineer poses on the helipad of the Turkish drilling vessel Yavuz in the Eastern Mediterranean off Cyprus, Aug. 6, 2019. (Reuters)
TT
20

EU Welcomes Turkish Ship's Return to Port from near Cyprus

A Turkish Petroleum (TPAO) engineer poses on the helipad of the Turkish drilling vessel Yavuz in the Eastern Mediterranean off Cyprus, Aug. 6, 2019. (Reuters)
A Turkish Petroleum (TPAO) engineer poses on the helipad of the Turkish drilling vessel Yavuz in the Eastern Mediterranean off Cyprus, Aug. 6, 2019. (Reuters)

A Turkish drill ship has left the area where it was operating southwest of Cyprus and reached Turkey's coast for maintenance in a move the European Union said would help ease tensions in the Eastern Mediterranean.

Refinitiv tracking data showed the Yavuz vessel reached shore and the Energy Ministry said it would now prepare for work in a new location.

EU member Cyprus' internationally recognized Greek Cypriot government has long been at loggerheads with Turkey over the demarcation of maritime waters and other issues. Turkish vessels began drilling for oil and gas near Cyprus last year.

EU leaders last Friday assured Cyprus the bloc would punish Turkey if it continues drilling in disputed Mediterranean areas, after resisting Cypriot calls to impose sanctions on Ankara.

The Yavuz was to be operating southwest of Cyprus until Oct. 12. Greece, a close ally of Cyprus, had called the work provocative.

The ship finished work at the Selcuklu-1 well on April 24 and returned to Tasucu Port, the energy ministry said. "Following preparatory work at the port, Yavus will continue drilling operations in a new location," it said.

A spokesman for the EU executive, the European Commission, said: "The departure constitutes another welcome step towards de-escalation ... and we hope for similar and further moves in this direction."

"It's an important signal," he told a regular briefing.

Turkish seismic research vessel Barbaros Hayrettin Pasa remains off southeastern Cyprus and its operations there have been extended to Oct. 18.

Regional tensions simmered after Turkish and Greek frigates collided at sea in August near a Turkish exploration vessel, but calmed after Turkey and Greece agreed to resume bilateral "exploratory talks" that ended in 2016.

NATO announced last Thursday that Greece and Turkey, both alliance members, had set up a "military de-confliction mechanism" to avoid accidental clashes at sea.

The island of Cyprus was split after a 1974 Turkish invasion spurred by a brief coup engineered by the military then ruling Greece.

Turkey has no diplomatic relations with Cyprus and instead recognizes a breakaway Turkish Cypriot state in the north of the island.



Iran's Hackers Keep a Low Profile after Israeli and US Strikes

Illustrative image of a man typing coded symbols on a computer (File photo: Reuters)
Illustrative image of a man typing coded symbols on a computer (File photo: Reuters)
TT
20

Iran's Hackers Keep a Low Profile after Israeli and US Strikes

Illustrative image of a man typing coded symbols on a computer (File photo: Reuters)
Illustrative image of a man typing coded symbols on a computer (File photo: Reuters)

After Israeli and American forces struck Iranian nuclear targets, officials in both countries sounded the alarm over potentially disruptive cyberattacks carried out by the Iranian hackers.

But as a fragile ceasefire holds, cyber defenders in the United States and Israel say they have so far seen little out of the ordinary – a potential sign that the threat from Iran’s cyber capabilities, like its battered military, has been overestimated.

There has been no indication of the disruptive cyberattacks often invoked during discussions of Iran’s digital capabilities, such as its alleged sabotage and subsequent break-ins at US casinos or water facilities.

"The volume of attacks appears to be relatively low," said Nicole Fishbein, a senior security researcher with the Israeli company Intezer. "The techniques used are not particularly sophisticated."

Online vigilante groups alleged by security analysts to be acting at Iran’s direction boasted of hacking a series of Israeli and Western companies in the wake of the airstrikes.

A group calling itself Handala Hack claimed a string of data heists and intrusions, but Reuters was not able to corroborate its most recent hacking claims. Researchers say the group, which emerged in the wake of Palestinian group Hamas’ October 7, 2023, attack on Israel, likely operates out of Iran’s Ministry of Intelligence.

Rafe Pilling, lead threat intelligence researcher at British cybersecurity company Sophos, said the impact from the hacking activity appeared to be modest.

“As far as we can tell, it's the usual mix of ineffectual chaos from the genuine hacktivist groups and targeted attacks from the Iran-linked personas that are likely having some success but also overstating their impact,” he said.

Iran's mission to the United Nations in New York did not respond to a request for comment. Iran typically denies carrying out hacking campaigns.

Israeli firm Check Point Software said a hacking campaign it ties to Iran’s Revolutionary Guards has in recent days sent phishing messages to Israeli journalists, academic officials and others.

In one case, the hackers tried to lure a target to a physical meeting in Tel Aviv, according to Sergey Shykevich, Check Point’s threat intelligence group manager. He added that the reasoning behind the proposed meeting was not clear.

Shykevich said there have been some data destruction attempts at Israeli targets, which he declined to identify, as well as a dramatic increase in attempts to exploit a vulnerability in Chinese-made security cameras – likely to assess bomb damage in Israel.

The pro-Iranian cyber operations demonstrate an asymmetry with pro-Israeli cyber operations tied to the aerial war that began on June 13.

In the days since the start of the conflict, suspected Israeli hackers have claimed to have destroyed data at one of Iran’s major state-owned banks. They also burned roughly $90 million in cryptocurrencies that the hackers allege were tied to government security services.

Israel's National Cyber Directorate did not return a message seeking comment.

Analysts said the situation is fluid and that more sophisticated cyber espionage activity may be flying under the radar.

Both Israeli and US officials have urged industry to be on the lookout. A June 22 Department of Homeland Security bulletin warned that the ongoing conflict was causing a heightened threat environment in the US and that cyber actors affiliated with the Iranian government may conduct attacks against US networks.

The FBI declined to comment on any potential Iranian cyber activities in the United States.

Yelisey Bohuslavskiy, the cofounder of intelligence company Red Sense, compared Iran’s cyber operations to its missile program. The Iranian weapons that rained down on Israel during the conflict killed 28 people and destroyed thousands of homes, but most were intercepted and none significantly damaged the Israeli military.

Bohuslavskiy said Iranian hacking operations seemed to work similarly.

“There is a lot of hot air, there is a lot of indiscriminate civilian targeting, and - realistically - there are not that many results,” he said.