Pakistan Petroleum Limited
Incident posture
Linked entities
- Victim
- Pakistan Petroleum Limited
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Pakistan Petroleum Limited experienced a ransomware attack that encrypted its servers, deleted backups, and led to a demand for payment while threatening to leak exfiltrated operational, contract, and employee data. The attack suspended financial operations for two days, though the company said core operational systems remained unaffected and it reported the incident to law enforcement while negotiating with the attackers.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 6, 2025, Pakistan Petroleum Limited detected a cybersecurity incident involving a ransomware intrusion targeting parts of its IT infrastructure. The attackers, operating under the alias “Blue Locker,” encrypted PPL’s servers and blocked access to backups. They demanded a ransom in exchange for a decryption tool and a promise not to leak sensitive data. A ransomware note was received from an external actor identifying themselves as “Proton.” In an email sent to PPL employees, the hackers stated that computers and servers were encrypted, backups were deleted from the network and copied, and that they had stolen business data and employee information, including TMC Data related to Sui and Adhi fields and various contracts. The message warned that any attempt to modify or recover files independently could result in permanent data loss.
As a result of the encryption, PPL’s entire financial system was brought to a standstill, and financial operations remained suspended for two days. The administration reported losing control over the company’s financial operations during the incident. While select non‑critical IT services were temporarily suspended as a precaution, core operational systems remained unaffected and joint‑venture partners and external stakeholders continued to operate without disruption. The attack raised concerns about the cybersecurity resilience of critical national infrastructure, particularly in the energy sector, and prompted alerts to other oil and gas companies to take precautionary measures.
PPL’s internal cybersecurity protocols were immediately activated, and its IT and cybersecurity teams, working with external experts, implemented containment measures including the temporary suspension of select non‑critical IT services. The company’s multi‑layered cybersecurity framework helped isolate the threat rapidly. PPL confirmed that the incident had been reported to relevant law enforcement and regulatory authorities, and investigations are ongoing in coordination with those agencies. A comprehensive forensic analysis is being conducted to assess the scope of the breach and to reinforce cyber resilience. Teams are working diligently to restore full system functionality in a secure and phased manner. According to sources, PPL’s IT experts and management are in negotiations with the hackers, who have taken control of the IT system for the past two days, and the government and relevant authorities have been fully informed about the situation, with a request made for assistance in restoring the company’s systems.
Sources
Sources available to members: 1 source.