CSIDB logo
Incident

Hibiscus Petroleum

Incident posture

Attack window
Oct 2019
Location
Malaysia
Status
Historical
CIA posture
Available to members
Updated
2025-11-02 00:00

Linked entities

Victim
Hibiscus Petroleum
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hibiscus Petroleum experienced a cyber attack targeting its IT systems, prompting the company to isolate and partially shut down affected components to contain the incident. The organization initiated gradual restoration efforts while confirming that production operations remained unaffected throughout the event. No operational disruptions occurred despite the temporary IT system compromises.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Hibiscus Petroleum, a Malaysian energy company, experienced a cybersecurity incident affecting its IT systems during the first week of October 2019. The company publicly disclosed the attack on October 7, 2019, indicating the compromise occurred at some point in the preceding days. Upon detecting the intrusion, the organization's response team isolated the compromised segments of its network infrastructure to prevent lateral movement by threat actors. This containment strategy involved partially shutting down affected systems while maintaining operational continuity for production assets. The company did not specify whether the attack vector involved malware, phishing, or external exploitation of vulnerabilities in its brief announcement.

Technical recovery operations commenced immediately following system isolation, with Hibiscus Petroleum prioritizing gradual restoration of services over rapid reactivation. The restoration process proceeded under heightened security monitoring to detect potential residual threats or secondary attack attempts. Throughout the incident response period, the company maintained that its hydrocarbon production operations remained unaffected, suggesting physical industrial control systems were either segregated from compromised IT infrastructure or not directly targeted. No evidence emerged in available disclosures regarding data exfiltration, ransomware deployment, or financial demands against the organization. The company's public communications focused exclusively on containment and restoration efforts without detailing forensic findings about attacker identity, motives, or specific techniques employed in the breach.

Sources

Sources available to members: 1 source.

CSIDB