Cyberattack
Petrochemical Plant
Saudi petrochemical plant — Triton/Trisis safety-system malware
June–August 2017
Saudi Arabia (plant identified in press reporting as Petro Rabigh)
Map
22.7400, 39.0300
What happened
Attackers deployed malware known as Triton, Trisis or HatMan against Schneider Electric Triconex safety instrumented systems at a Saudi petrochemical plant, attempting to reprogram the controllers that provide the last line of automated protection against dangerous plant conditions. A coding error tripped the plant into a safe shutdown in August 2017, leading to discovery. It was the first publicly known malware designed specifically to target industrial safety systems, a capability security researchers class as potentially lethal. The plant is widely identified in press reporting as Petro Rabigh; the marker is placed at the Rabigh complex.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Petrochemical Plant
- Current temperature
- Loading…
- Latitude
- 22.7400°
- Longitude
- 39.0300°
Attribution
Attributed to TsNIIKhM (Russian state research institute)
The US Treasury sanctioned Russia's Central Scientific Research Institute of Chemistry and Mechanics in October 2020 for building the attack tools, and a TsNIIKhM researcher was indicted. The institute denied involvement.
