Menu
Browse

Cyber Incident Victim: Hexion Inc.

Date:

Mar 2019

Location:

United States of America

Summary

A ransomware attack targeted two affiliated chemical companies, Hexion and Momentive, causing a global IT outage that disrupted operations by encrypting files and rendering systems inoperable with blue screen errors. The incident, attributed to LockerGoga ransomware based on identical ransom notes, led to complete network and email access loss, forcing the deployment of emergency response teams and the procurement of hundreds of replacement computers. Data on compromised devices was deemed unrecoverable, necessitating the creation of new email domains for employees. The attack mirrored prior LockerGoga incidents, indicating potential coordination, though official disclosures from the affected firms remained minimal amid recovery efforts.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 12, 2019, Hexion and Momentive—two U.S.-based chemical companies specializing in resins, silicones, and industrial materials, and controlled by the same investment fund—experienced a coordinated ransomware attack that caused severe operational disruption. The attack triggered a "global IT outage," as described in an internal email from Momentive CEO Jack Boss, prompting both companies to deploy emergency "SWAT teams" to manage the crisis. Forensic analysis of the ransom message displayed on compromised Momentive laptops identified the malware as LockerGoga, based on identical language and formatting to prior attacks, including the contemporaneous incident affecting aluminum manufacturer Norsk Hydro. The ransomware encrypted files on Windows-based systems across the organizations, rendering them inaccessible and causing blue screen errors. Employees lost all network and email access, paralyzing routine operations.

Cyber Incident Image

The attack’s impact was immediate and extensive, with Momentive’s leadership concluding that data on affected devices was irrecoverable, leading to the procurement of "hundreds of new computers" to replace compromised systems. Employees were issued new email accounts under the domain "momentiveco.com" after the original infrastructure remained inoperable. Hexion publicly acknowledged efforts to restore operations but provided no technical specifics, while both companies maintained minimal external communication; calls to Hexion’s hotline went unanswered. The incident underscored LockerGoga’s pattern of targeting multinational industrial firms, despite its noted inefficiency in generating ransom payments for attackers. No ransom amount or payment confirmation was disclosed in available communications, and the full scope of data loss or operational downtime remained unquantified in public statements.

Sources
Sources available to members
1 source