Oltenia Energy Complex, Romania's largest coal-based energy producer, suffered a ransomware attack attributed to the Gentlemen ransomware group. The incident, detected on December 26, resulted in the encryption of documents and files, and caused temporary unavailability of critical IT applications, including ERP systems, document management, email services, and the company website. Despite the disruption, the operation of the National Energy System was not jeopardized, and the company's activity was only partially affected.
Upon discovery, the affected systems were isolated and IT teams began rebuilding infrastructure using existing backups. The company reported the incident to the National Cyber Security Directorate, the Ministry of Energy, and filed a criminal complaint with law enforcement agencies. Investigations are ongoing to determine the full impact and whether any data was exfiltrated prior to encryption. The Gentlemen ransomware group is known for exploiting compromised credentials and targeting internet-exposed services, deploying ransom notes and encrypting files with the .7mtzhh extension.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By 2025-12-29, reporting attributed the Oltenia Energy Complex intrusion to the Gentlemen ransomware group. At that time, the group had not listed the company on its leak site, suggesting negotiations or an unfinalized extortion phase.
After detecting the attack, the company notified Romanian authorities, cooperated with the National Cyber Security Directorate and DIICOT, and filed a criminal complaint. Law enforcement and incident responders opened an investigation into the ransomware incident.
Following the attack, Oltenia Energy Complex isolated affected systems and began restoring services using backups and newly built infrastructure. The organization also continued assessing the scope of the incident, including whether any data was exfiltrated.
On 2025-12-26, Romania's Oltenia Energy Complex suffered a ransomware attack that disrupted its IT infrastructure and encrypted documents and applications. Affected systems reportedly included ERP, email, and the company website, while the National Energy System was not impacted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcestiripesurse.ro
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.