CSIDB logo
Incident

CPC Corporation

Incident posture

Attack window
May 2020
Location
Taiwan
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
CPC Corporation
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted Taiwan's state oil company, attributed by authorities to the Winnti group or a closely affiliated entity linked to Chinese state-sponsored activities. The incident disrupted customer payment card operations for fuel purchases and forced infrastructure rebuilding, though energy production remained unaffected. This attack formed part of a broader pattern compromising multiple critical domestic energy and technology organizations in Taiwan through ransomware campaigns.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 4, 2020, Taiwan’s state-owned oil company CPC Corporation sustained a ransomware attack that disrupted operations. Taiwanese authorities attributed the attack to the Winnti hacking group or a closely related entity, citing forensic evidence including configuration files and domain names left behind by the attackers. The Ministry of Justice publicly disclosed this assessment in an official statement, linking Winnti to Chinese state-sponsored cyber operations. While the ransomware did not compromise CPC’s core energy production capabilities, it significantly impacted customer-facing systems. Specifically, the attack prevented customers from using CPC payment cards to purchase gasoline, indicating disruption to retail transaction processing infrastructure. CPC initiated recovery efforts that required rebuilding portions of its compromised IT environment.

The incident occurred amid a broader ransomware campaign targeting Taiwan’s critical infrastructure sectors. The Ministry of Justice noted multiple “important domestic energy and technology companies” had been affected by similar attacks in recent weeks, though it did not explicitly name additional victims beyond CPC. Local media reports interpreted the ministry’s statement as confirming CPC’s involvement alongside other unnamed organizations. The attack highlighted operational risks to Taiwan’s strategic assets, with reconstruction of compromised systems representing a primary organizational response. No ransomware variant or specific financial demands were disclosed in available reporting. The Chinese government did not publicly respond to Taiwan’s allegations of Winnti’s involvement.

Sources

Sources available to members: 1 source.

CSIDB