Oil or fuel facility

Saudi Aramco — Shamoon wiper attack

15 August 2012

Saudi Arabia

What happened

The Shamoon wiper virus infected Saudi Aramco's corporate IT network, erasing data and overwriting the master boot record on roughly 30,000 to 35,000 Windows-based workstations, forcing the company to disconnect its systems from the internet and rebuild much of its network from scratch. The attack reportedly began with a phishing email that compromised a domain administrator's credentials months earlier. Aramco's oil production and industrial control systems were not affected; the disruption was confined to corporate IT, though it took the company roughly two weeks to restore normal business operations such as employee email and about a month to fully recover. The marker is placed at Aramco's Dhahran headquarters.

Evidence
Documented
Confidence
High
Infrastructure
Oil or fuel facility
Latitude
26.2900°
Longitude
50.1100°

Attribution

Claimed by A group calling itself "Cutting Sword of Justice"; US officials later attributed the attack to Iran

The hacktivist claim of responsibility was contemporaneous; the US government's attribution to Iran came in later official statements and was not confirmed in the original 2012 reporting.

Sources

  1. Compromise of Saudi Aramco and RasGasCouncil on Foreign Relations, Cyber Operations Tracker · Incident reporting