CSIDB logo
Incident

Transnet

Incident posture

Attack window
Dec 2017
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2026-01-30 10:14

Linked entities

Victim
Transnet
Threat actors
0 actors
Sources
0 sources

Timeline

Occurred
Dec 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Unauthorized cryptocurrency mining operations utilizing Monero were discovered on the company's computer systems, with mining software automatically downloaded from the web before being removed. The incident prompted implementation of preventive measures to block similar unauthorized activities in the future, though it raised concerns about potential negative impacts on processing capacity due to resource misuse. A company executive warned that such exploitation of corporate hardware for cryptocurrency production could affect operational productivity, while cybersecurity experts predicted increased targeting of organizations for covert mining operations. Russian legal frameworks at the time prescribed prison terms for server hacking, with planned extensions to penalties, amid broader regulatory concerns about cryptocurrency-related financial crimes including money laundering and terrorism financing risks acknowledged by central authorities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late 2017, Russian state-controlled pipeline operator Transneft discovered unauthorized cryptocurrency mining activities on its computer systems. The incident occurred when software designed to mine Monero—a cryptocurrency positioned as an alternative to Bitcoin—was automatically downloaded from the internet onto a company computer. Transneft spokesperson Igor Demin confirmed the mining software was subsequently deleted after detection. The company implemented new security programs to block similar unauthorized downloads in the future, though technical specifics of these controls were not disclosed. Vice President Vladimir Rushailo publicly acknowledged the incident during a company meeting on December 14, 2017, warning that such unauthorized use of corporate hardware could negatively impact processing capacity. Rushailo, a former interior minister, did not elaborate on the operational consequences or duration of the mining activity.

The incident highlighted emerging cybersecurity risks associated with cryptocurrency proliferation. Information security expert Pavel Lutsik predicted increased targeting of corporate infrastructure for cryptocurrency mining, noting attackers' financial motivations and relative anonymity. Russian legislation at the time imposed six-year prison sentences for server hacking, with penalties scheduled to increase to ten years in 2018. Transneft's disclosure coincided with ongoing Russian governmental efforts to regulate virtual currencies, with central bank officials repeatedly expressing concerns about cryptocurrency's potential misuse for money laundering and terrorism financing. No attribution to specific threat actors or further technical details about the intrusion vector were disclosed by Transneft representatives.

Sources

Sources available to members: 0 sources.

CSIDB