Cyber Incident Victim: POSCO Engineering & Construction
Date:
Mar 2023
Location:
Viet Nam
Summary
POSCO Engineering & Construction, alongside affiliated firms PetroVietnam and Long Son Petrochemicals, experienced a data leak involving infrastructure and piping schematics, employee information, business registration documents, and contract agreements. The breach was publicly disclosed by threat actor Kernelware on BreachForums, who claimed to release the data freely without ransom demands or prior victim notification; the actor's history included leaking datasets from other entities like Acer Taiwan and Acronis, often citing boredom or minor motives before announcing a temporary hiatus due to personal commitments. The shared project documents among the three firms obscured whether the compromise originated from a single source or multiple systems.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On March 14, 2023, a threat actor known as Kernelware published a data leak on BreachForums involving three Vietnamese firms: PetroVietnam, Long Son Petrochemicals, and POSCO Engineering & Construction. The leak included schematics for infrastructure and piping, business registration documents, employee information, and contract agreements. Files from the dump bore stamps indicating collaboration between the three entities on a shared project, though it remained unclear whether the data originated from one compromised server or multiple systems. Kernelware did not attempt to contact the affected companies or demand payment, stating the data was released freely with the intent to "humiliate" the organizations out of boredom. The actor declined to disclose the intrusion method when questioned but emphasized no extortion or sale of the data was involved. DataBreaches.net contacted PetroVietnam for comment but received no immediate response.

Kernelware had been active on BreachForums since August 2022, frequently leaking datasets without charge and occasionally offering databases for sale. In the weeks preceding the incident, the actor leaked data purportedly linked to Acer Taiwan, HDB Financial Services (initially misidentified as HDFC Bank), and Acronis. The Acronis leak triggered a public response from the company, which asserted the breach stemmed from compromised credentials of a single customer account used for diagnostic uploads, downplaying its significance. Kernelware acknowledged the Acronis data as "minor and not really interesting," framing the leak as an act of humiliation rather than strategic theft. The actor announced a temporary halt to leaks due to upcoming exams following the disclosure involving POSCO E&C and the other Vietnamese firms. No public statements or containment measures from POSCO E&C or PetroVietnam were documented at the time of reporting.
