Major German fuel storage provider hit with cyberattack, working under limited operations
Full article824 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Global operations of Oiltanking were not affected.
A cyberattack struck major German oil storage company Oiltanking GmbH Group on Sunday, the company confirmed to CyberScoop in a statement.
The BlackCat ransomware appears to be the source of the attack, according to a report by Germany’s intelligence authority obtained by Handelsblatt.
The attack affected the IT systems of Oiltanking as well as the mineral oil trade company Mabanaft, German news outlet Handelsblatt first reported. Both companies belong to the Hamburg-based Marquard & Bahls group, one of the world’s largest energy supply companies.
The attack shut down the oil tank company’s IT systems, according to a statement by the company’s head of corporate communications, Claudia Wagner. Oiltanking’s German subsidiary which operates all terminals in Germany is operating at limited capacity.
Oiltanking’s global operations were not affected.
“We are working to solve this issue according to our contingency plans, as well as to understand the full scope of the incident,” Wagner wrote to CyberScoop in an email. “We are undertaking a thorough investigation, together with external specialists and are collaborating closely with the relevant authorities.”
Oiltanking Germany owns and operates 11 terminals with a total storage capacity of 2.375 million cubic meters of fuel. Clients of the company include a number of mid-sized companies as well as oil corporation Shell. Royal Dutch Shell is now re-routing oil supplies to other storage, the company told Reuters.
As of December, Black Cat had the seventh-most victims of all ransomware groups tracked by Palo Alto Network’s Unit 42 threat intelligence unit. The group uses the coding language Rust, which is highly customizable and allowed the group to build a reputation for individualized attacks. It also pays affiliates, who rent out its attack infrastructure, a high commission compared to other groups.
The attack comes as Germany, which is heavily reliant on Russian oil, considers pulling out of a major gas pipeline deal with Russia if the nation further invades Ukraine. German intelligence also issued a warning last week about ongoing cyberattacks by APT27, a Chinese-based hacking group.
“There isn’t enough information to say who was responsible, but regardless the attackers saw an opportunity to put even more pressure on Germany, which is one of the largest consumers of Russian gas in Europe,” Hank Schless, senior manager for security solutions at Lookout, wrote in an email to CyberScoop. “This is the perfect example of using a high-pressure situation to create opportunity for malicious cyber activity, which attackers do as often as they can.”
Cyberattacks against the energy sector have proven extremely destabilizing in the past. A May ransomware attack against U.S.-based Colonial Pipeline caused a panic at American gas stations.
Updated 2/2/2022: To include additional information about the nature of the attack.
More Scoops
German political party targeted by SVR-linked group in spearphishing campaign, Mandiant says
The group may have been seeking insights on shifting European sentiments on Ukraine, threat analysts suggest.
Ransomware spree hitting European oil, transport companies
Cyberattack disrupts Colonial Pipeline, which transports 100 million gallons of fuel daily
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/major-german-fuel-storage-provider-hit-with-cyberattack-working-under-limited-operations/