INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Conpet's data stolen in Romania pipeline attack by Lazarus Group

| 2026-02-12 19:16 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
On February 5, 2026, the Qilin ransomware gang breached Conpet S.A.'s corporate IT infrastructure, resulting in data exfiltration. The Romanian national oil pipeline operator confirmed that nearly 1TB of documents were stolen from its systems, including personal information such as names, postal addresses, and bank account numbers. The attack is believed to have been carried out by the Qilin ransomware gang, although no direct attribution has been made. Conpet S.A. collaborated with the Romanian National Cyber Security Directorate in the investigation, but operations remained unaffected. Scammers impersonating employees of well-known organizations, including Conpet S.A., are now targeting individuals potentially affected by the incident, requesting personal or financial information for fraudulent activities.
Technical Mitigations AI-generated
• Patch Conpet S.A.'s systems to address potential vulnerabilities exploited by the Qilin ransomware gang. • Monitor for leaked images of internal documents with financial information and passport scans, which may be used in phishing attacks or other fraudulent schemes. • Block or hunt for indicators such as personal identification numbers (PIN) and bank account numbers that were compromised during the breach.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
Target & Sectors
RO
energyenergy
Incident Timeline
‎2026/02/12
Threat actors, specifically the Qilin ransomware gang, stole nearly 1TB of documents from Romania's oil pipeline operator Conpet S.A.
data_breach 1 TB
Tactical Metrics
Metrics
data_breach
1
Tb
Intelligence Sources