Romania’s national oil pipeline operator Conpet confirmed a cyberattack that disrupted parts of its corporate IT environment and rendered its public website inaccessible, while stating that core oil transport operations were not impacted. Conpet reported that its operational technology environment—including SCADA and telecommunications systems—remained fully functional, and said it took immediate mitigation steps, engaged Romania’s national cybersecurity authorities to support the investigation and recovery, and filed a criminal complaint.
The Qilin ransomware operation (a Russian-speaking ransomware-as-a-service group) claimed responsibility by listing Conpet on its leak site and alleging theft of nearly 1 TB of data; the group posted samples it says are internal documents, including financial records and passport scans. Reporting characterized Qilin as a highly active and destructive actor with prior victims across public and private sectors internationally, and noted the incident occurs amid a broader pattern of ransomware activity affecting Romanian organizations and critical services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-05, the Qilin ransomware group added Conpet to its Tor-based leak site and claimed responsibility for the attack. The gang alleged it had stolen about 1 TB of sensitive data and published sample files, including financial information and passport scans, as proof.
In a statement issued on 2026-02-04, Conpet publicly confirmed the cyberattack and said the incident did not affect operational activity, company stability, or its ability to meet contractual obligations. The company reiterated that the National Oil Transport System remained safe and fully functional.
On the day of detection, Conpet activated mitigation measures, began investigating with Romania’s national cybersecurity authorities, and filed a criminal complaint with DIICOT. The response was aimed at containing the incident while maintaining normal transport operations.
On 2026-02-03, Romania’s national oil pipeline operator Conpet detected a cyberattack that disrupted parts of its business IT infrastructure and temporarily took its public website offline. The company said operational technology, including SCADA and telecommunications systems, continued functioning normally and oil transport operations were not disrupted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcedatabreaches.net
Open sourcescworld.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.