1 August 2022

Natural gas pipeline operator Creos Luxembourg reportedly hit with ransomware


Natural gas pipeline operator Creos Luxembourg reportedly hit with ransomware

A cybercrime gang behind the AlphV ransomware said it successfully attacked Creos Luxembourg, an operator of electricity networks and natural gas pipelines in the Grand Duchy of Luxembourg.

Last week, Creos confirmed it suffered a cyberattack, which took place during the night of July 22-23, 2022. The company did not disclose the nature of the cyber incident, but said that the supply of electricity and gas was not affected.

On their dark web data leak site the AlphV (better known as BlackCat) operators claimed to have breached Creos Luxembourg and stolen more than 150 GB of corporate data, including sensitive information such as contracts, agreements, copies of IDs, invoices, emails and more. The ransomware operators also promised to release more files in the near future.

The AlphV/BlackCat ransomware is believed to be a rebrand of the BlackMatter ransomware which was a rebrand of the DarkSide ransomware that hit the energy pipeline operator Colonial Pipeline, one of the US' largest pipelines, in May 2021. Due to the attack Colonial Pipeline temporarily shut down its 5,500 miles of pipeline to contain the threat.

In May 2022, the US Pipeline and Hazardous Materials Safety Administration (PHMSA) proposed a nearly $1 million fine for management failures at Colonial Pipeline that contributed to widespread fuel shortages along the US East Cost following a 2021 ransomware attack.


Back to the list

Latest Posts

Iranian hackers exploit RMM tools to deliver malware

Iranian hackers exploit RMM tools to deliver malware

One of the aspects of MuddyWater's strategy involves exploiting Atera's free trial offers.
24 April 2024
Ongoing malware campaign targets multiple industries, distributes infostealers

Ongoing malware campaign targets multiple industries, distributes infostealers

The campaign leverages a CDN cache domain as a download server, hosting malicious HTA files and payloads.
24 April 2024
US charges four Iranian hackers for cyber intrusions

US charges four Iranian hackers for cyber intrusions

The group targeted both both government and private entities.
24 April 2024