Oil & Gas

Industry

Cyberattack at TIMEC Oil & Gas

April 7, 2025

Pasadena, Texas-based TIMEC Oil & Gas, Inc. suffered a cyberattack where employees’ personally identifiable information ended up stolen.
On July 30, TIMEC reported it suffered a data breach this past April where sensitive personally identifiable information and protected health information located within in its systems suffered a compromise.
TIMEC detected unauthorized access to its internal ERP system between April 7 and April 10 during which certain employees’ direct deposit information ended up altered.

read more

Cyberattack At AK Oil Services Firm, Doyon

April 1, 2024

Fairbanks, Alaska-based Doyon, Limited, which operates a diverse family of companies, including more than a dozen for-profit businesses across the nation in the areas of oil field services, utility management, engineering management, suffered a cyberattack in April.
“On or about April 2, 2024, we discovered that on or about April 1, 2024, an unauthorized actor or actors accessed and acquired files from Doyon’s IT systems,” said a letter sent out to victim of the attack. “We initiated an investigation, retained an outside incident response company, and notified law enforcement.”
The company said it conducted a review with the assistance of external experts to determine if personal information ended up stolen in the attack. Through its investigation, the company found personal information such as names and other pertinent data the company did not reveal.

read more

Oil-Gas Producer, DJH Services, Hit In Cyberattack

February 13, 2025

Oil and Gas producer, DJH Services LLC, suffered a cyberattack in February and is now informing victims what personally identifiable information ended up stolen.
Houston, Texas-based DJH Services also wrote the notice on behalf of its companies, Harrison Interests, Ltd., Fulshear Oil & Gas, and Ramro.
“On February 13, 2025, DJH discovered a cyber incident affecting our network. Immediately upon detecting this incident, we took steps to secure our environment, began remediation and recovery efforts, and launched a thorough investigation in partnership with third-party cybersecurity experts,” the company said in the notice. “We also reported this matter to the Federal Bureau of Investigation.”

read more

Ransomware Attack At EB Archbald & Associates, a Provider To Oil-Gas Producers

March 23, 2025

There was a ransomware attack at EB Archbald & Associates, Inc., which provides energy production accounting services to oil and gas producers and operators.
“On March 23, 2025, we discovered that our company had been the target of a so-called ‘ransomware’ attack,” the Oklahoma City, Oklahoma-based company said in a notice to its 17,000 victims. “The attackers hacked into our system and utilized software to encrypt all data on our servers and Microsoft cloud-based portal. In a subsequent communication the attackers demanded payment of a large sum of money in exchange for their release of a ‘decryption key.’
“We immediately contacted the local office of the Federal Bureau of Investigation (FBI) and notified them of the attack. Per recommendations received from the FBI we refused to meet the attackers’ extortion demands. Five days after their initial attack, and following our refusal to meet their monetary demand, we received a communication from the attackers claiming that they had downloaded information from our systems which they intended to release on the world wide web,” the company said in the notice.

read more

Pakistan Petroleum Limited Foiled Ransomware Attempt

August 6, 2025

Pakistan Petroleum Limited (PPL), an oil and gas exploration firm, reported a ransomware attack on parts of its IT infrastructure, detected on August 6, 2025. The incident was swiftly contained with no compromise of critical systems or sensitive data. PPL shared that a ransomware note was received from an external actor and that no contact was made by PPL. Blue Locker claimed the attack.

Pakistan’s National Cyber Emergency Response Team (NCERT) issued a severe risk advisory to 39 key government ministries and institutions following sophisticated ransomware attacks that significantly impacted the country’s critical infrastructure, particularly the oil and gas sector.

read more

Contract Drilling Operator, Kanai Drilling, Data Encrypted

May 17, 2025

Bakersfield, California-based contract drilling operator, Kanai Drilling Limited, suffered a cyberattack where data ended up encrypted and attackers stole personally identifiable information.
“On or about May 19, 2025, Kenai Drilling Limited became aware of a cyber security breach of confidential information which occurred between May 17-May 18, 2025,” said a letter sent out to victims of the attack.
In the letter, the privately held drilling contractor said unauthorized “parties” hacked into Kenai’s Document File Server and gained access to sensitive and confidential information without the knowledge or consent of Kenai.
“The culprits accessed and encrypted files that included employee names, social security numbers, wage information, addresses, email addresses, and phone numbers set up by Kenai for each employee. This breach did not expose the employee’s personnel files kept internally at Kenai,” the notice said.

read more

Oil and Gas producer, DJH Services, Suffers Cyberattack

February 13, 2025

Oil and Gas producer, DJH Services LLC, suffered a cyberattack in February and is now informing victims what personally identifiable information ended up stolen.
Houston, Texas-based DJH Services also wrote the notice on behalf of its companies, Harrison Interests, Ltd., Fulshear Oil & Gas, and Ramro.
“On February 13, 2025, DJH discovered a cyber incident affecting our network. Immediately upon detecting this incident, we took steps to secure our environment, began remediation and recovery efforts, and launched a thorough investigation in partnership with third-party cybersecurity experts,” the company said in the notice. “We also reported this matter to the Federal Bureau of Investigation.”

read more

Ransomware Hits Provider to Oil-Gas Producers

March 23, 2025

There was a ransomware attack at EB Archbald & Associates, Inc., which provides energy production accounting services to oil and gas producers and operators.
“On March 23, 2025, we discovered that our company had been the target of a so-called ‘ransomware’ attack,” the Oklahoma City, Oklahoma-based company said in a notice to its 17,000 victims. “The attackers hacked into our system and utilized software to encrypt all data on our servers and Microsoft cloud-based portal. In a subsequent communication the attackers demanded payment of a large sum of money in exchange for their release of a ‘decryption key.’
“We immediately contacted the local office of the Federal Bureau of Investigation (FBI) and notified them of the attack. Per recommendations received from the FBI we refused to meet the attackers’ extortion demands. Five days after their initial attack, and following our refusal to meet their monetary demand, we received a communication from the attackers claiming that they had downloaded information from our systems which they intended to release on the world wide web,” the company said in the notice.

read more

Data Breach at Colorado-based Trinity Petroleum Management

October 14, 2024

Denver, Colorado-based Trinity Petroleum Management, LLC suffered a cyberattack after discovering an unauthorized party was able to access information that had been provided to the company.
Trinity Petroleum said the incident resulted in an unauthorized party being able to access consumers’ personally identifiable information, which includes first and last names, addresses, and Social Security numbers. The incident affected 46,659 victims, the company said in an advisory.

read more

Costa Rica RECOPE Switches to Manual Operations

November 27, 2024

Costa Rica’s state oil refinery RECOPE switched to manual operations Wednesday after a ransomware attack targeted its computer systems. While fuel sales continue without interruption, RECOPE has directed all staff to avoid using digital platforms as cybersecurity teams assess the damage from the early morning attack on November 27.

This incident was the first real-world test of the U.S. State Department’s new rapid response tool for cybersecurity incidents; Foreign Assistance Leveraged for Cybersecurity Operational Needs, or FALCON. FALCON is one of several U.S. initiatives developed to bolster allies and infuse global digital norms with American values.

read more