HomeSecurityRompetrol gas station network hit by Hive ransomware

Rompetrol gas station network hit by Hive ransomware

The Rompetrol gas station network in Romania was hit by a ransomware attack. Rompetrol, which is a subsidiary of KMG International, announced today that it is facing a «complex cyberattack» that forced it to shut down its website and the Fill&Go service at fuel stations.

See also: Telegram chats are not end-to-end encrypted by default

Rompetrol gas station network hit by Hive ransomware

Fuel station service «Fill&Go», the websites fell

Today, the Romanian oil provider Rompetrol announced that it is battling a «complex cyberattack».

BleepingComputer learned that behind this attack is the Hive ransomware gang and they are demanding a ransom of many millions.

Η Rompetrol είναι ο διαχειριστής του μεγαλύτερου διυλιστηρίου πετρελαίου της Ρουμανίας, της Petromidia Navodari.

See also: FBI: Ragnar Locker ransomware has targeted 52 organizations belonging to US critical infrastructure

As one of the largest oil companies, KMG International operates in fifteen countries across Europe, Central Asia and North Africa. KMG's main activities include refining, marketing, trading, production and oil industry services such as drilling, EPCM and transportation.

Rompetrol gas station network hit by Hive ransomware

BleepingComputer observed that the websites of KMG and Rompetrol are not accessible as of today and the Fill&Go application no longer works. However, we learned that the company's email system (Microsoft Outlook) remains functional.

Rompetrol gas station network hit by Hive ransomware

KMG has already notified the National Cybersecurity Directorate of Romania (DNSC), which is in continuous contact with the organization to fix the problem and provide the necessary assistance.

According to an anonymous tip from BleepingComputer, the threat actor also reached the internal IT network of the Petromidia refinery.

However, as Rompetrol states, the works at the Petromidia refinery are not affected.

In an email to employees, the company said the attack was detected at 21:00 (local time) on Sunday and that it affected “most of the IT services”.

Hive is demanding a ransom of 2 million dollars

BleepingComputer learned that the Hive Ransomware gang is behind the attack on KMG's subsidiary, Rompetrol.

We learned that Hive is demanding a ransom of 2 million dollars from Rompetrol to obtain the decryptor and not leak allegedly stolen data.

Rompetrol Hive ransomware

The Hive ransomware gang is more active and aggressive than the leak site shows, with its subsidiaries attacking an average of three companies each day since the operation became known in late June 2021.

See also: Samsung hacked: Hackers stole the source code of Galaxy devices

The group is known to employ a diverse set of tactics, techniques, and procedures, making it difficult for organizations to defend against its attacks, as the FBI has previously stated .

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS