Pakistan Petroleum Limited Foiled Ransomware Attempt

November 10, 2025

INCIDENT

Pakistan Petroleum Limited (PPL), an oil and gas exploration firm, reported a ransomware attack on parts of its IT infrastructure, detected on August 6, 2025. The incident was swiftly contained with no compromise of critical systems or sensitive data. PPL shared that a ransomware note was received from an external actor and that no contact was made by PPL. Blue Locker claimed the attack.

Pakistan’s National Cyber Emergency Response Team (NCERT) issued a severe risk advisory to 39 key government ministries and institutions following sophisticated ransomware attacks that significantly impacted the country’s critical infrastructure, particularly the oil and gas sector.

Incident Date

August 6, 2025

Location

Pakistan

Estimated Cost


No cost values disclosed.

Type of Malware

No Malware identified

Threat Source