Breaking

Romania’s largest oil company ‘Rompetrol’ hit by Hive ransomware operators

Romanian gas station ‘Rompetrol’ is hit by a ransomware attack. Rompetrol is a subsidiary of KMG International which made an announcement stating that they are dealing with a complex cyberattack that made them shut down their websites and their Fill&Go service at gas stations.

Rompetrol’s Hive ransomware attack and the ransom demands

Rompetrol is the largest oil company in Romania and has a capacity of over five million tons a year. The company operates in Europe, North Africa, and Central Asia.  

It is suspected that the entity behind the Rompetrol ransomware attack is Hive ransomware operators and the ransom demands are suspected to be in several millions. Rompetrol announced the same on social media today. As of now KMG has intimated Romanian National Directorate of Cyber Security (DNSC) who is actively resolving the situation now.

“To protect the data, the company has temporarily suspended the operation of the websites and the Fill&Go service, both for the fleets and for the private customers,” said a Rompetrol spokesperson.”The activity of Rompetrol gas stations is carried out normally, the customers having at their disposal the option of payment in cash or by bank card.”

As per an anonymous tip shared with BleepingComputer, the hackers might have reached the  internal network of Petromidia refinery that belongs to Rompetrol. However, the company states otherwise.

As per an email to Rompetrol’s employees, the attack was first detected at 21:00 on Sunday affecting their IT services.

Details on Hive ransomware operators

Hive ransomware operators have been lively recently targeting at least three organizations a day. And the Hive ransomware operators are demanding two million as ransom from the Rompetrol. Hive employs a variety of tactics, techniques and hacking methodologies to breach networks, which is why the Hive ransomware gang is a sophisticated group that organizations should be concerned about.

Recent attacks have Hive includes compromising Memorial Health System which made them cancel surgeries and other diagnostic procedures including patient information.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, and Twitter.

You can reach out to us via Twitter/ Facebook or mail us at admin@thecybersecuritytimes.com for advertising requests.

Share the article with your friends
William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

Recent Posts

Top 9 Best Log Management Tools for 2025

Discover the best log management tools for efficient system management and monitoring. Learn about the…

6 months ago

Top 4 Remote Support Tools for 2025- Best Remote Support Solution

Taking remote of devices and managing them will make thing simple for IT admins. In…

6 months ago

Top 5 Best Unified Endpoint Management (UEM) Software for 2025

In 2024, the Unified Endpoint Management Software market will continue to evolve and here are…

6 months ago

Top 5 Threat Intelligence Tools For 2025

Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…

7 months ago

Top 5 Best Microsoft Intune Alternatives to Consider for 2025

Explore the top 5 best Microsoft Intune alternatives, comparing key features, user reviews, and capabilities…

8 months ago

Recast Software: Advanced Endpoint Management and Security Tools for IT Teams

Recast Software offers a suite of tools designed to enhance and simplify endpoint management in…

1 year ago