HomeSecurityConpet cyberattack: Romania's national oil pipeline operator targeted

Conpet cyberattack: Romania's national oil pipeline operator targeted

Conpet , Romania’s main oil pipeline operator, was recently the target of a serious cyberattack that affected its corporate systems and took the company’s website offline. The incident was reported on Tuesday and comes at a time of increasing ransomware attacks on key infrastructure in the country.

Conpet

Impact on business operations

Conpet operates nearly four kilometers of pipelines, supplying domestic and imported crude oil, gasoline and liquid ethane to refineries across Romania. Despite the attack, the company assured that its core operations were not affected: the pipelines continue to operate normally, while the SCADA and telecommunications systems remain secure.

In a press release issued on Wednesday, Conpet stressed that "the IT infrastructure was affected, but operations continue without interruption. The company's website www.conpet.ro remains temporarily out of service."

See also: Conduent: New details about last year's data breach

Dealing with the attack

The company is working with national cybersecurity authorities to restore the affected systems and has notified the Directorate for the Investigation of Organized Crime and Terrorism (DIICOT), while also filing a criminal complaint for the incident.

Conpet, however, has yet to provide details on the nature of the attack. According to unconfirmed reports, the Qilin ransomware gang claimed responsibility, posting Conpet on the dark web leak site. The attackers claim to have stolen around 1TB of documents and have posted photos of internal documents, including financial details and passport scans, as proof of the breach.

Conpet cyberattack: Romania's national oil pipeline operator targeted

The Qilin threat and its past

Qilin emerged in August 2022 as a Ransomware-as-a-Service (RaaS) operation under the name “Agenda”. Over the past four years, it has claimed responsibility for nearly 400 attacks, targeting high-profile targets including Nissan, Japanese beer company Asahi, publishing giant Lee Enterprises, pathology services provider Synnovis and Australian Court Services Victoria. Qilin’s activity highlights the growing international threat of organized ransomware attacks on critical infrastructure.

See also: Italy thwarted Russian cyberattacks targeting Winter Olympics

The cyberattack on Conpet follows other attacks that have hit critical sectors in Romania in recent years. In December 2024, Romanian Waters and the Oltenia Energy Complex were targeted by ransomware, while Electrica Group was attacked by the Lynx ransomware. In addition, in February 2024, over 100 hospitals in the country were put out of service after their healthcare systems were breached by the Backmydata ransomware

This pattern highlights the need to strengthen cybersecurity in critical infrastructure, as attacks now affect not only business data, but also services vital to the public.

Conpet cyberattack: Romania's national oil pipeline operator targeted

The importance of protecting critical infrastructure

Cybersecurity experts point out that attacks on companies like Conpet can have multiple impacts: from financial losses to disruptions in the supply of fuel and energy products. Cooperation with national and international authorities, immediate notification of competent law enforcement authorities and the use of advanced detection and remediation technologies are critical steps in dealing with such incidents.

See also: Substack data leak exposed emails and phone numbers

The Conpet case shows that cyberattacks are no longer an exclusive IT issue, but a national security issue, with their impacts extending to the economy, energy and daily life. As ransomware attacks evolve and become more targeted, the need for preventive measures and rigorous cybersecurity in critical organizations becomes increasingly urgent.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS