Cyber Incident Victim: Transnet
Date:
Dec 2017
Location:
Russia
Summary
Unauthorized cryptocurrency mining operations utilizing Monero were discovered on the company's computer systems, with mining software automatically downloaded from the web before being removed. The incident prompted implementation of preventive measures to block similar unauthorized activities in the future, though it raised concerns about potential negative impacts on processing capacity due to resource misuse. A company executive warned that such exploitation of corporate hardware for cryptocurrency production could affect operational productivity, while cybersecurity experts predicted increased targeting of organizations for covert mining operations. Russian legal frameworks at the time prescribed prison terms for server hacking, with planned extensions to penalties, amid broader regulatory concerns about cryptocurrency-related financial crimes including money laundering and terrorism financing risks acknowledged by central authorities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In late 2017, Russian state-controlled pipeline operator Transneft discovered unauthorized cryptocurrency mining activities on its computer systems. The incident occurred when software designed to mine Monero—a cryptocurrency positioned as an alternative to Bitcoin—was automatically downloaded from the internet onto a company computer. Transneft spokesperson Igor Demin confirmed the mining software was subsequently deleted after detection. The company implemented new security programs to block similar unauthorized downloads in the future, though technical specifics of these controls were not disclosed. Vice President Vladimir Rushailo publicly acknowledged the incident during a company meeting on December 14, 2017, warning that such unauthorized use of corporate hardware could negatively impact processing capacity. Rushailo, a former interior minister, did not elaborate on the operational consequences or duration of the mining activity.

The incident highlighted emerging cybersecurity risks associated with cryptocurrency proliferation. Information security expert Pavel Lutsik predicted increased targeting of corporate infrastructure for cryptocurrency mining, noting attackers' financial motivations and relative anonymity. Russian legislation at the time imposed six-year prison sentences for server hacking, with penalties scheduled to increase to ten years in 2018. Transneft's disclosure coincided with ongoing Russian governmental efforts to regulate virtual currencies, with central bank officials repeatedly expressing concerns about cryptocurrency's potential misuse for money laundering and terrorism financing. No attribution to specific threat actors or further technical details about the intrusion vector were disclosed by Transneft representatives.
