Oil & Gas

Industry

Oil Provider, SM Energy, Hit in Attack

May 15, 2026

Denver, Colorado-based oil exploration firm, SM Energy Company, suffered a cyberattack in May where personally identifiable information ended up stolen in the hack.
SM Energy ended up hit in the attack May 15, where unauthorized threat actors gained access to certain company systems.
“Based on our investigation, we determined on June 30, 2026, that an unauthorized third party accessed certain SM Energy systems and obtained files containing certain of your personal information,” the company said in a notice mailed out to victims in July.

read more

Cyberattack at Oil Equipment Provider, Cardinal Services

July 28, 2026

New Iberia, Louisiana-based oil and gas equipment and services provider, Cardinal Services LLC, suffered a cyberattack in July where personally identifiable information ended up stolen in the hack.
The July 28 data breach affected Cardinal Services and compromised the personal and medical information of 2,241 individuals, according to a report with the Texas Attorney General’s office.
Founded in 2012, the company provides slickline operations, coiled tubing, nitrogen and fluid pumping, pressure control rentals, and over-the-road crane rentals. It provides services in shallow and deep waters of the Gulf of Mexico, plus U.S. land markets.

read more

Cyberattack at Ecopetrol, Colombia Energy Provider

July 17, 2026

Colombia’s energy giant, Ecopetrol S.A., suffered a cyberattack as threat actors gained unauthorized access to certain digital resources as well as an attempted ransomware attack that ended up blocked by the controls implemented across the company and its subsidiaries, the company said Friday.
The unauthorized access affected cloud-based file storage environments of approximately 15 subsidiaries (including the company), resulting in the download of data associated with approximately 3,300 user accounts.
As a result of the attack, reported Friday, July 17, the unidentified threat actor communicated extortion demands, threatening to publicly disclose the stolen information.

read more

Drilling Provider SDI Management Cyberattack

February 25, 2026

Mt Morris, Pennsylvania-based gas facility and drilling provider SDI Management LLC (SDIM) suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“SDI Management detected a network compromise that could have impacted your personal information,” the company said in a notice to victims. “We have no indication that your information has been or will be misused.”
“SDIM identified and responded to unauthorized network activity on February 25, 2026,” the company said. “We immediately secured and remediated the compromise, engaged additional third-party experts, and commenced an investigation.”

read more

Oil Producer, Capital Star Oil & Gas, Suffers Cyberattack

November 3, 2025

Houston, Texas-based upstream oil producer, Capital Star Oil & Gas, Inc. suffered a cyberattack in November and is now letting victims know their personally identifiable information ended up stolen in the hack.
Capital Star Oil & Gas, Inc. takes the privacy and security of the data under our care very seriously and we regret any concern or inconvenience this may cause.
“On November 3, 2025, we detected suspicious activity within our network, the company said in a notice to victims of the attack. “We promptly initiated an investigation of the matter and engaged cybersecurity specialists to assist with the incident response.”

read more

Oil & Gas Producer, Murex Petroleum, Suffers Cyberattack

May 27, 2025

Spring, Texas-based Murex Petroleum Corporation suffered a cyberattack in May and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On or about May 27, 2025, we detected unauthorized access to our network,” the company said in a letter to victims. “Upon learning of the issue, we secured our network and commenced a prompt and thorough investigation.”
Murex said as a part of its investigation, it worked very closely with external cybersecurity professionals experienced in handling these types of incidents.

read more

Cyber‑Related Disruption Forces Temporary Suspension of PDVSA Oil Cargo Deliveries

December 15, 2025

Petróleos de Venezuela, S.A. (PDVSA) — the Venezuelan state‑owned oil company — experienced a cyberattack in mid‑December 2025 that disrupted its central administrative and operational systems, including systems used for coordinating oil cargo deliveries. The attack forced PDVSA to isolate its oilfields, refineries, ports and other facilities from its compromised central network to contain the incident. As a result, scheduled oil cargo deliveries and exports were suspended for several days, as terminal workers resorted to manual record‑keeping and contingency measures to avoid further operational stoppages.

By 17  December 2025, PDVSA reported that it had resumed loading and delivering crude and fuel cargoes at its terminals after the cyber‑related suspension and operational isolation. PDVSA said the company could restart operations by manually recording deliveries while maintaining isolation from compromised systems, and exports resumed despite ongoing geopolitical and logistical pressures.

read more

Canadian Cyber Centre Warns of Hacktivists Abusing Internet‑Accessible Industrial Control Systems

October 29, 2025

Multiple incidents have been reported in Canada where internet‑accessible industrial control systems (ICS) have been manipulated by opportunistic actors (hacktivists). Attackers altered water pressure values at a water treatment facility, resulting in degraded service for the community. An Automated Tank Gauge (ATG) was manipulated at an oil and gas company, triggering false alarms. Temperature and humidity values were manipulated at a farm grain silo, potentially leading to unsafe conditions if not discovered in time.

read more

Cyberattack Shutdown Russian Oil Giant Lukoil

March 26, 2025

Cyberattack hit Russian oil giant Lukoil resulting in a complete shutdown of internal systems and caused disruptions across several regions, including corporate offices and gas stations. Lukoil’s management instructed employees via SMS to shut down all work computers after an unusual error message showed on many computers. The attack resulted in partial halt in fuel distribution to gas stations & other consumers for several days.

read more

Cyberattack Hits Oilfield Services Provider, NPK

October 28, 2024

Oilfield site access solution provider, The Woodlands, Texas-based NPK International Inc. suffered a cyberattack in October last year and is now letting victims know the details of the attack.
NPK completed an investigation involving suspicious activity within its network that occurred on October 28, 2024.
“When NPK first learned of this activity, it immediately took steps to secure its network, notified law enforcement, and engaged third-party forensic firms with experience helping other companies in similar situations,” the company said in a notice to victims.
Through the investigation, NPK learned an unauthorized actor accessed its network between October 28, 2024, and October 29, 2024. The threat actor copied certain files from its servers. NPK conducted a thorough review of the relevant files, and on August 12, 2025, the review determined that one or more files contained the personal information of victims, including the name, Social Security number, and financial account number.

read more