Menu
Browse

Cyber Incident Victim: Sinopecs Shengli Oilfield

Date:

Aug 2017

Location:

China

Summary

A ransomware attack targeted Sinopec's Shengli Oilfield, compromising 21 internet terminals and prompting the company to disconnect internet access for offices lacking virus protection systems. The incident disrupted operations at one of China's largest oil production facilities, which had been a significant contributor to Sinopec's output since the mid-1960s. This cyberattack followed a global pattern of ransomware incidents affecting major corporations, leading to precautionary network isolation measures to contain further spread.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On August 21, 2017, Sinopec’s Shengli Oilfield publicly disclosed a ransomware attack targeting its internet-connected systems. The malicious software infected 21 internet terminals, prompting the company to announce immediate containment measures through an official statement on its website. As a direct response to the incident, Shengli Oilfield initiated plans to disconnect internet access for all office computers lacking antivirus protection systems. The attack disrupted normal operations at certain facilities of the oilfield, though the company did not specify whether production systems were compromised. Shengli characterized the event as a ransomware incident but did not identify the specific malware variant or disclose whether attackers demanded payment.

Cyber Incident Image

Shengli Oilfield, operational since 1964 and historically one of Sinopec’s largest production bases, became the latest entity affected by a global wave of ransomware attacks targeting commercial organizations that year. The company’s response focused on isolating vulnerable systems by severing external network connectivity for unprotected devices, indicating an effort to prevent further propagation of the malware within its infrastructure. No details were provided regarding the attack’s origin, data exfiltration, or financial impact. The incident underscored operational vulnerabilities in legacy industrial systems, though Shengli’s public communications emphasized containment rather than production stoppages or safety compromises. Recovery efforts centered on restoring secured connectivity after implementing antivirus protections across affected terminals.

Sources
Sources available to members
1 source