Menu
Browse

US-based server owned by an engineering company in the oil, gas, and chemical industries

Aliases: 3 aliases
Primary URL Location Industry
www[.]fluor[.]com
Country United States of America
Commercial Icon
Commercial
Profile

The organisation is an engineering company that provides services to the oil, gas, and chemical industries in the United States. Its core activities involve delivering engineering solutions such as design, analysis, and project support for facilities and operations within those sectors. It serves clients across the domestic market, focusing on the technical needs of energy and chemical production. The company's work is rooted in the engineering discipline applied to hydrocarbon and chemical processing environments.

The company's headquarters is located in the United States of America, as indicated in its official records. No further details about its organisational size, employee count, or geographic footprint are provided in the source material. Therefore, any description of scale must be limited to the confirmed location of its HQ.

A distinguishing aspect of the organisation's infrastructure is its use of a VoIP system based on the Asterisk FreePBX platform for internal communications. In February 2018, this VoIP server became the target of a hacking campaign that exploited known vulnerabilities in the software. Attackers installed a custom PHP web shell, which granted them remote control over the server and access to call metadata, recorded conversations, and the ability to spoof outgoing calls. The compromise enabled extensive surveillance capabilities, allowing the intruders to monitor communication patterns and extract sensitive audio data while obscuring their activities.

The server that was compromised is explicitly described as being owned by the engineering company, indicating that the asset is part of its own IT environment rather than a third‑party service. No information is provided about parent‑company relationships, subsidiaries, or ownership structures beyond this statement. Consequently, the organisational structure remains undefined in the available sources beyond the confirmation of domestic ownership.

The incident highlights the importance of securing VoIP deployments within engineering firms that support critical industries. It also demonstrates how a breach of a communications platform can lead to broader surveillance risks. These points are drawn solely from the reported event and the organisation's described sector focus.

Incidents
Linked incidents available to members
1 incident