Menu
Browse

Cyber Incident Victim: Anadarko Petroleum Corporation

Date:

Apr 2020

Location:

Algeria

Summary

Anadarko Petroleum Corporation subsidiary Berkine was compromised by the Maze ransomware group, resulting in theft and public leakage of over 500MB of sensitive data including financial records, strategic plans, production metrics, and employee personal information. The attackers employed double-extortion tactics, exfiltrating confidential documents prior to encryption and threatening further releases to coerce payment, with some stolen materials already disseminated online for potential phishing campaigns.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On April 1, 2020, the Maze ransomware group executed a cyberattack against Berkine, resulting in the theft of over 500MB of confidential corporate data. The attackers exfiltrated databases containing sensitive operational and financial documents, including detailed budgets, organizational strategies for 2020, production quantity records, and cost-per-barrel calculations. Employee records were also compromised, encompassing contact information and travel documents. Maze employed its characteristic double-extortion tactic, encrypting systems while simultaneously threatening to release stolen data unless ransom demands were met. The group followed through on its threat by leaking portions of the data publicly, specifically targeting information related to Berkine's ownership structure and financial operations.

Cyber Incident Image

The leaked documents included investment plans, mission budgets for Berkine's parent companies, and strategic objectives for the fiscal year. Security researchers at Under the Breach confirmed the authenticity of the published materials, which appeared on hacker forums accessible to malicious actors. This incident aligned with Maze's established pattern of escalating pressure tactics, as previously documented by the French National Agency for Security of Information Systems (ANSSI) following their January 2020 attack on a Bouygues subsidiary. The group maintained an active leak site where they periodically released additional stolen data to incentivize payment from victims. The exposure of employee personally identifiable information and proprietary business metrics created significant operational and reputational risks for the organization, though specific containment measures or incident response actions by the victim were not disclosed in available reporting.

Sources
Sources available to members
1 source