HomeSecurityConpet: Ransomware attack led to data theft

Conpet: Ransomware attack led to data theft

Romania’s national oil pipeline operator, Conpet SA, has confirmed that it was the victim of a cyberattack by the Qilin ransomware gang, resulting in the theft of corporate data. The incident occurred last week and is already causing serious concern, as it concerns an organization that is crucial to the country’s energy security.

Conpet data theft

In a press release issued the following day, Conpet said that the attackers had managed to breach the company’s IT infrastructure. However, according to the same statement, the company’s core oil and gas transportation operations were not immediately affected. This suggests that, at least at this stage, the attack was more aimed at intercepting data than disrupting critical services.

Collaboration with the National Cybersecurity Directorate

In a later update, Conpet SA announced that it is in close cooperation with the Romanian National Cybersecurity Directorate (DNSC), which is investigating the incident. The involvement of state bodies is considered necessary, as this is an attack on a company of strategic importance linked to critical infrastructure.

See also: Google: Hackers target global defense industry

In a statement to technology outlet BleepingComputer, the company confirmed that the attack led to a data leak, but could not yet determine the exact volume of information stolen, due to the ongoing investigation.

Conpet: Ransomware attack led to data theft

Qilin's claims and the leaked sample

The Qilin group, one of the most active ransomware gangs in recent years, claims to of documents nearly 1TB from Conpet's systems. To prove the breach, it leaked a sample of 16 images that include internal financial documents and passport scans.

Of particular concern is the fact that some of the documents are marked "confidential" and have dates up to November 2025, indicating access to recent and sensitive data.

Information that may have been leaked includes names, addresses, personal identification numbers, and even bank accounts.

The risk of fraudulent actions and phishing attacks

In its latest announcement, Conpet warned that the compromised data could be used for fraudulent activities. The company urges those who may be affected to be particularly cautious of urgent requests via phone, email or other communication channels.

See also: Google: Hackers exploit Gemini AI for all stages of attacks

Cybercriminals often exploit such leaks to launch phishing attacks, posing as employees of well-known organizations. Their goal is to extract financial information or access to accounts, using the credibility of real data.

Conpet: Ransomware attack led to data theft

How can citizens be protected?

Experts recommend that any suspicious request should be immediately verified through the organization's official contact details, as listed on the official website or verified social media accounts. We should never trust contact details included in the suspicious message itself.

Prevention , in such cases, is the most powerful tool against the escalation of fraud .

Conpet as critical energy infrastructure

Conpet SA is a strategic company under the control of the Romanian Ministry of Energy. It manages the transportation of crude oil and natural gas through a pipeline network of approximately 3,800 kilometers.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Crazy ransomware: Abuse of legitimate employee monitoring tool

This specific attack highlights how vulnerable critical energy infrastructure remains to modern ransomware threats, reinforcing the need for investments in cybersecurity and the shielding of government organizations.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS