← All incidents
Incident dossier · Rank #27

Red Sea Subsea Cable Cuts — Rubymar Anchor Severs AAE-1, Seacom/TGN-EA and EIG off Yemen

AAE-1 / EIG / Seacom / Tata (TGN) consortia 2024-02-24 3408h 0m core impact NetworkSupply chain

On 24 February 2024 three submarine cable systems — Seacom (which Kentik groups with TGN-EA), AAE-1 and EIG — were severed off the west coast of Yemen in the Red Sea. The generally-accepted cause is the anchor of the MV Rubymar, an abandoned cargo ship struck by Houthi forces on 18 February, dragging across the cable corridor after the anchor was dropped when the vessel came under fire. The cuts degraded a large share of Asia-Europe-Middle-East transit (commonly cited at ~25%, though that figure is unattributed in reachable sources) and were felt across East Africa and the Middle East. Physical repair did not begin until July 2024, when an E-Marine cable ship restored AAE-1 first and then the remaining two cables. The cause is the accepted narrative rather than a forensic consortium finding; TGN-EA is named alongside Seacom by Kentik, but whether it is a physically distinct 4th cable or shares the Seacom system remains only partly corroborated.

Failure cascade

Failure cascade: trigger → fault → downstream impactTriggerPrimary faultDownstream impactTrigger — Network (2024-02-24)Trigger · Network2024-02-242024-02-24Primary fault at AAE-1 / EIG / Seacom / Tata (TGN) consortia — Red Sea cable corridor (Bab-el-Mandeb / off west coast of Yemen)AAE-1/EIG/SeacomRed Sea cable corridor (Bab-el-Mandeb / off west coast of Yemen)Red Sea cable corridorDownstream service degraded by the fault: Seacom submarine cable (Kentik lists the damaged system as 'Seacom/TGN-EA')Seacom submarine cableDownstream service degraded by the fault: AAE-1 (Asia-Africa-Europe-1)AAE-1Downstream service degraded by the fault: EIG (Europe India Gateway)EIGDownstream service degraded by the fault: ~25% of Asia-Europe / Asia-Middle-East transit capacity degraded (screening estimate, unattributed)~25% of Asia-Europe /

Trigger → primary fault → downstream blast radius, derived from the sourced root cause and affected-services record.

Facility & location

Operator
AAE-1 / EIG / Seacom / Tata (TGN) consortia
Data center
Red Sea cable corridor (Bab-el-Mandeb / off west coast of Yemen)
Location
Bab-el-Mandeb, Yemen
Date
2024-02-24

Impact & scale

Users affected
Reported as tens of millions across East Africa and the Middle East in the seed brief, but UNCORROBORATED — no reachable source provides an absolute affected-user count; documented impact is country-level connectivity degradation plus one operator's earnings hit.
Financial
Not disclosed in absolute terms. Only quantified figure: Seacom's contribution to 30%-shareholder Remgro's headline earnings fell to ~R2M from ~R32M the prior year (~R30M / ~94% drop), attributed mainly to once-off cable-repair costs. Absolute repair spend never published.
Scope
Major regional connectivity incident — multi-cable, multi-country, ~5-month restoration
Services / systems down
  • Seacom submarine cable (Kentik lists the damaged system as 'Seacom/TGN-EA')
  • AAE-1 (Asia-Africa-Europe-1)
  • EIG (Europe India Gateway)
  • ~25% of Asia-Europe / Asia-Middle-East transit capacity degraded (screening estimate, unattributed)

Impact data & metrics

Subsea cable systems severed3 (Seacom/Tata TGN-Eurasia, AAE-1, EIG); HGC reportedly cited 4
Asia-Europe / Red Sea capacity lost~25% ('a quarter')
End-user traffic loss observed (Feb 22-28)~0 (no material loss across affected East-African markets)
Vessel drift distance while not under command>70 km (43 mi) by 26 Feb 2024
Anti-ship missiles fired at Rubymar2 (one struck)
Crew evacuated24, by container ship Lobivia
Restoration time (AAE-1)~4-5 months (pending 13 May 2024 -> completed July 2024)
Detection date of cable damage24 Feb 2024 (Cloudflare); exact UTC not published
Industry baseline: faults from anchors/fishing~70-80% of all cable faults
Vessel profile~171 m bulk carrier, built 1997; fertiliser cargo (press/CENTCOM: ~21,000 t ammonium-phosphate-sulphate)
Fault-water depth regimeshallow Bab-el-Mandeb corridor where dragged anchors hook armoured cable

Magnitude profile

Magnitude sub-scores (0–10)Magnitude sub-scores (0–10)Users 7Users affected (0–10) — breadth of the user/customer population impacted. — scored 7/10.Financial 4Financial impact (0–10) — direct + consequential cost. — scored 4/10.Duration 8Outage duration (0–10) — how long service was degraded/down. — scored 8/10.Blast 8Blast radius (0–10) — how wide the fault propagated across systems/regions. — scored 8/10.
Magnitude 7.0 = blast 8×0.35 + users 7×0.25 + financial 4×0.20 + duration 8×0.20 (sub-scores 0–10 · weighted composite)

Blast radius and duration dominate: multiple international backbones down for roughly five months across a chokepoint carrying a large share of Asia-Europe traffic. User score is provisional — the 'tens of millions' figure is uncorroborated. Financial score is low because only one operator's ~R30M earnings delta is documented; the absolute repair bill and wider economic cost were never disclosed.

Sequence of events (SOE)

Phased sequence of events2024-02-18 · TRIGGER — Houthi forces fire two anti-ship missiles at MV Rubymar off Yemen; one strikes, severely damaging and disabling the Belize-flagged, Lebanese-operated (GMZ) bulk carrier (~171 m, built 1997, Marshall Is.-registered owner).TRIGGER2024-02-182024-02-18 · TRIGGER — All 24 crew evacuated by the container ship Lobivia; the disabled, not-under-command vessel is left adrift with its anchor down.TRIGGER2024-02-182024-02-18 to 02-26 · CASCADE — Unmanned vessel 'moved more than 70 kilometres (43 mi) while not under command', dragging its anchor across the Bab-el-Mandeb seabed cable corridor.CASCADE2024-02-18 to 02~2024-02-24 · IMPACT — Under the leading hypothesis the dragging anchor shears three armoured subsea systems — Seacom/Tata TGN-Eurasia, AAE-1 and EIG; Wikipedia calls it 'One hypothesis' and the cause 'currently unknown'.IMPACT~2024-02-242024-02-24 · DETECTION — Optical continuity lost; operators' line-monitoring/OTDR systems register faults at measured distances; Cloudflare Radar dates the cable damage to 24 Feb 2024 and names the three systems.DETECTION2024-02-242024-02 (late) · DETECTION — Loss observed out-of-band via BGP routing changes, latency and traffic monitoring by Kentik (Doug Madory), Cloudflare Radar and NetBlocks — no facility alarm involved.DETECTION2024-02 (late)2024-02-22 to 02-28 · DETECTION — Cloudflare: 'no loss of traffic was observed across these countries in Cloudflare Radar' (Tanzania, Kenya, Uganda, Mozambique) — fault visible on capacity/routing telemetry while end-user traffic stayed up.DETECTION2024-02-22 to 022024-02 (late) · MITIGATION — Operator HGC reported rerouting affected traffic onto surviving cables and terrestrial paths (protection switching, not suppression).MITIGATION2024-02 (late)2024-02 (late) · MITIGATION — Affected wavelengths dropped and re-groomed onto surviving fibres and parallel/terrestrial routes — optical-layer isolation of the severed segments.MITIGATION2024-02 (late)2024-02 (late) · IMPACT — Roughly a quarter (~25%) of Red Sea / Europe-Asia-Middle East capacity lost; Wikipedia states the damage 'affected 25% of the internet traffic between Europe, Asia and the Middle East'.IMPACT2024-02 (late)2024-02 (late) · IMPACT — Despite the capacity loss, Cloudflare telemetry shows little-to-no end-user traffic loss — parallel and terrestrial diversity absorbed the load.IMPACT2024-02 (late)2024-03-02 · CASCADE — MV Rubymar sinks, ending the drift.CASCADE2024-03-022024-02 to 07 · RECOVERY — Repair-ship dispatch gated by war-risk: active missile/drone threat, war-risk insurance and naval-security constraints delay intervention for months.RECOVERY2024-02 to 072024-05 (by 13 May) · RECOVERY — AAE-1 repairs still 'pending due to the refusal of permits from the Yemeni Government'.RECOVERY2024-05 (by 13 M2024-07 · RESTORED — 'In July 2024, repairs were successfully carried out on the AAE-1 cable' — an ~4-5 month restoration versus the days-to-weeks typical in a permissive environment.RESTORED2024-07post-incident · RESTORED — No consortium- or regulator-issued root-cause report published; cause officially 'currently unknown' — the record remains telemetry-vendor analysis plus press.RESTOREDpost-incident

Root cause

PROXIMATE MECHANISM (mapped from "ignition source / equipment" — this is a mechanical cable-severance incident, not a fire, so no ignition, combustion chemistry, or equipment make/model applies). The damaging "equipment" was the bower anchor and chain of the MV Rubymar — a Belize-flagged, Lebanese-operated (GMZ Ship Management Company S.A.) bulk carrier of about 171 m, built 1997, whose registered owner is Golden Adventure Shipping S.A. (Marshall Islands); she was laden with fertiliser (widely reported by press/CENTCOM as ~21,000 t of ammonium-phosphate-sulphate). On 18 Feb 2024 Houthi forces fired two anti-ship missiles off Yemen; one struck the Rubymar, severely damaging and disabling her, and all 24 crew were evacuated by the container ship Lobivia (Wikipedia "MV Rubymar"). The abandoned, not-under-command vessel was left adrift with its anchor down and, per Wikipedia, "by 26 February it had moved more than 70 kilometres (43 mi) while not under command," dragging across the Bab-el-Mandeb seabed cable corridor. Under the leading hypothesis the dragging anchor severed several undersea cables (Wikipedia "MV Rubymar": "its dragging anchor may have damaged several undersea internet cables"). The Rubymar sank on 2 March 2024. A dragged anchor hooking and shearing armoured cable in the shallow Bab-el-Mandeb corridor is the classic, ICPC-documented top fault mode. ATTRIBUTION IS UNPROVEN — this must be stated plainly. No operator or investigator published a positive, instrumented root cause tying the specific anchor to the specific breaks (no recovered anchor marks, no matched fault-coordinate-versus-anchor-track survey). Wikipedia "AAE-1" labels it "One hypothesis for the source of the damage" and says the cause is "currently unknown"; the attribution rests only on temporal and spatial coincidence (drift window 18-26 Feb, cuts ~24 Feb, same corridor). The Houthis denied targeting cables; alternative explanations were floated but unsubstantiated. LATENT ROOT (the real systemic lesson). The design/redundancy failure is ROUTE CONCENTRATION: three independent systems — Seacom/Tata TGN-Eurasia, AAE-1 and EIG (Cloudflare Radar names exactly these three; HGC was reported to count four) — share the same narrow, contested off-Yemen corridor, so a single seabed event severed all at once. There is no enforced anchoring-exclusion or cable-protection zone there. The "maintenance/procedure" lapse is not a cable-O&M defect — the cables were in normal service and failed to external mechanical impact — but a maritime and governance one: a war-damaged, abandoned vessel was left adrift with its anchor down in a known cable corridor with no timely salvage or anchor-recovery (the security environment prevented it), and there was no agreed permitting/safe-passage regime for repair ships — Wikipedia records AAE-1 repairs stalled "due to the refusal of permits from the Yemeni Government." The ICPC baseline (~70-80% of cable faults from accidental human activity such as fishing and anchors) confirms an anchor strike is the single most expected fault mode, so the corridor lacked adequate anchoring protection rather than any cable being under-maintained.

Contributing factors

Correction of errors (COE)

Lessons learnt

Improvements & remediation

Comprehensive analysis

Nature of the incident — mechanical severance, not a fire

This is a subsea-cable incident with no data-centre, no combustion, no fixed-facility evacuation and no electrical de-energisation in the fire sense. The fire-report schema is therefore mapped, not applied literally: 'ignition source/equipment' becomes the dragging anchor and chain of MV Rubymar; 'detection' becomes network telemetry (BGP, latency, OTDR); 'suppression' becomes traffic rerouting; 'evacuation' refers to the vessel crew; 'emergency services' becomes repair-ship dispatch. Non-applicable fire categories are flagged, not invented.

Attribution: unproven, coincidence-based

No operator or investigator published a positive, instrumented root cause. Wikipedia calls the Rubymar anchor 'One hypothesis' and states the cause is 'currently unknown'. The case rests entirely on temporal and spatial coincidence: the vessel drifted >70 km with its anchor down between 18 and 26 February, and Cloudflare dated the cuts to 24 February in the same corridor. No recovered anchor marks and no matched fault-coordinate-versus-anchor-track survey exist. The dossier states this plainly rather than asserting a proven cause.

The real systemic lesson — corridor concentration

Three nominally independent systems (Seacom/Tata TGN-Eurasia, AAE-1, EIG) share the narrow, shallow, contested Bab-el-Mandeb corridor, so a single seabed event severed all at once. There is no enforced anchoring-exclusion zone, despite the ICPC baseline that ~70-80% of cable faults come from human activity such as anchoring and fishing. The failure is design redundancy (route diversity), not cable maintenance — the cables were in normal service and failed to external impact.

Why recovery took months — geopolitics, not engineering

Restoration was gated by access, not splice time. Wikipedia records AAE-1 repairs 'pending due to the refusal of permits from the Yemeni Government', compounded by active missile/drone threat, war-risk insurance and naval-security constraints. Repairs were completed in July 2024 — roughly 4-5 months, versus days-to-weeks in a permissive environment. The absence of a standing safe-passage/permitting regime for repair ships is the governance root of the prolonged outage.

Resilience that worked — capacity headroom vs end-user impact

Despite ~25% of Europe-Asia-Middle East capacity being lost, Cloudflare states 'no loss of traffic was observed across these countries in Cloudflare Radar' (Tanzania, Kenya, Uganda, Mozambique) during 22-28 February. Rerouting onto surviving fibres, parallel systems and terrestrial paths absorbed the load. The mitigation largely worked; the residual risk analysts flag is that losing more of the same corridor simultaneously would exhaust that headroom.

Technical deep-dive

FORENSIC FRAMING (method transparency): This is a physical subsea-cable incident. There was no data-centre alarm, no fire-suppression, no fixed-facility evacuation, and no electrical de-energisation in the fire sense. Each fire-schema category below is mapped to its subsea-cable equivalent; non-applicable items are flagged, not invented. Sourcing caveat: several primary pages (HGC newsroom, Seacom, Reuters, AP, Al Jazeera, The Register, Al Arabiya, Kentik deep-dive) returned 403/404 or could not be re-fetched; findings are grounded in the pages successfully retrieved on 2026-08-02 — Wikipedia "MV Rubymar", Wikipedia "AAE-1" and the Cloudflare Radar "Q1 2024 Internet Disruption Summary" — plus citation metadata those pages expose for Kentik (31 Mar 2024) and press. The ICPC 70-80% figure is a well-established industry baseline but the exact ICPC page could not be re-fetched this pass. DETECTION (= network telemetry / fault sensing). The cuts were detected not by any facility alarm but by out-of-band Internet telemetry: BGP routing changes, latency/traffic monitoring and cable-fault reporting by Kentik (Doug Madory), Cloudflare Radar and NetBlocks, plus operators' own line-monitoring/OTDR systems that register a fault as loss of optical continuity at a measured distance. Cloudflare Radar dated the damage to 24 Feb 2024 and named the Seacom/Tata cable, AAE-1 and EIG. Critically, for the East-African markets said to be affected (Tanzania, Kenya, Uganda, Mozambique) Cloudflare states "no loss of traffic was observed across these countries in Cloudflare Radar" during 22-28 Feb — the fault was visible on capacity/routing telemetry while end-user traffic largely stayed up. SUPPRESSION (= fault mitigation / protection switching). No fire-suppression applies. The functional equivalent — restoring service — was automatic and manual TRAFFIC REROUTING onto surviving cables and terrestrial paths. HGC was reported to have rerouted affected traffic. Effectiveness was partial-to-good: about a quarter of Red Sea / Europe-Asia-Middle East capacity was lost, yet Cloudflare saw no material end-user loss, indicating parallel Red Sea systems and terrestrial diversity absorbed the load. The residual risk analysts flag is that losing MORE of the corridor simultaneously would exhaust that headroom. EVACUATION (= the vessel, not the cable). All 24 Rubymar crew were evacuated by the container ship Lobivia after the 18 Feb strike. The abandonment is causally central — an unmanned, not-under-command vessel with anchor down drifted >70 km across the corridor. EMERGENCY SERVICES (= repair-ship dispatch). Response was measured in MONTHS, not minutes, gated by war-risk and jurisdiction: Wikipedia records AAE-1 repairs "still pending due to the refusal of permits from the Yemeni Government," compounded by active missile/drone threat, war-risk insurance and naval-security constraints. AAE-1 repairs were "successfully carried out" in July 2024 — an ~4-5 month restoration versus the days-to-weeks typical of a permissive environment. DE-ENERGISATION / ISOLATION (= wavelength/traffic isolation). Severed segments were isolated at the optical layer — affected wavelengths dropped and re-groomed onto surviving fibres and alternate cables. Subsea cables carry a repeater power feed, but no arc-flash/energised-equipment hazard was reported. CONTAINMENT / SPREAD. Impact was contained to the three cut systems and the East-Africa/Gulf markets that lean on them; there was no cascading physical spread. The systemic "spread" concern is corridor concentration: one dragging anchor took out three independent systems at once because the Bab-el-Mandeb chokepoint carries a large share of Europe-Asia capacity.

References & provenance

Sourced from public post-incident reports. Quotes are short attributed excerpts for provenance only; the analysis above is original and substantially shorter than its sources. Last verified 2026-08-01.

Root access required

The DC Incidents dossier is a root-only module. Sign in with an authorized account to continue.

Back to Home