CSIDB logo
Incident

Pakistan Petroleum Limited

Incident posture

Attack window
Aug 2025
Location
Pakistan
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-17 19:29

Linked entities

Victim
Pakistan Petroleum Limited
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Aug 2025
Disclosed
Aug 2025
Resolved
Pending

Summary

Pakistan Petroleum Limited experienced a ransomware attack that encrypted its servers, deleted backups, and led to a demand for payment while threatening to leak exfiltrated operational, contract, and employee data. The attack suspended financial operations for two days, though the company said core operational systems remained unaffected and it reported the incident to law enforcement while negotiating with the attackers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On August 6, 2025, Pakistan Petroleum Limited detected a cybersecurity incident involving a ransomware intrusion targeting parts of its IT infrastructure. The attackers, operating under the alias “Blue Locker,” encrypted PPL’s servers and blocked access to backups. They demanded a ransom in exchange for a decryption tool and a promise not to leak sensitive data. A ransomware note was received from an external actor identifying themselves as “Proton.” In an email sent to PPL employees, the hackers stated that computers and servers were encrypted, backups were deleted from the network and copied, and that they had stolen business data and employee information, including TMC Data related to Sui and Adhi fields and various contracts. The message warned that any attempt to modify or recover files independently could result in permanent data loss.

As a result of the encryption, PPL’s entire financial system was brought to a standstill, and financial operations remained suspended for two days. The administration reported losing control over the company’s financial operations during the incident. While select non‑critical IT services were temporarily suspended as a precaution, core operational systems remained unaffected and joint‑venture partners and external stakeholders continued to operate without disruption. The attack raised concerns about the cybersecurity resilience of critical national infrastructure, particularly in the energy sector, and prompted alerts to other oil and gas companies to take precautionary measures.

PPL’s internal cybersecurity protocols were immediately activated, and its IT and cybersecurity teams, working with external experts, implemented containment measures including the temporary suspension of select non‑critical IT services. The company’s multi‑layered cybersecurity framework helped isolate the threat rapidly. PPL confirmed that the incident had been reported to relevant law enforcement and regulatory authorities, and investigations are ongoing in coordination with those agencies. A comprehensive forensic analysis is being conducted to assess the scope of the breach and to reinforce cyber resilience. Teams are working diligently to restore full system functionality in a secure and phased manner. According to sources, PPL’s IT experts and management are in negotiations with the hackers, who have taken control of the IT system for the past two days, and the government and relevant authorities have been fully informed about the situation, with a request made for assistance in restoring the company’s systems.

Sources

Sources available to members: 1 source.

CSIDB