Oil or fuel facility
Saudi Aramco — Shamoon wiper attack
15 August 2012
Saudi Arabia
What happened
The Shamoon wiper virus infected Saudi Aramco's corporate IT network, erasing data and overwriting the master boot record on roughly 30,000 to 35,000 Windows-based workstations, forcing the company to disconnect its systems from the internet and rebuild much of its network from scratch. The attack reportedly began with a phishing email that compromised a domain administrator's credentials months earlier. Aramco's oil production and industrial control systems were not affected; the disruption was confined to corporate IT, though it took the company roughly two weeks to restore normal business operations such as employee email and about a month to fully recover. The marker is placed at Aramco's Dhahran headquarters.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Oil or fuel facility
- Latitude
- 26.2900°
- Longitude
- 50.1100°
Attribution
Claimed by A group calling itself "Cutting Sword of Justice"; US officials later attributed the attack to Iran
The hacktivist claim of responsibility was contemporaneous; the US government's attribution to Iran came in later official statements and was not confirmed in the original 2012 reporting.