Romania’s national oil pipeline operator Conpet reported a cyberattack that disrupted corporate IT services and took its public website offline, while stating that operational technology (including pipeline control and telecommunications systems) remained functional and oil transport continued. The Qilin ransomware group claimed responsibility, and reporting indicated the actor alleged data theft on the order of ~1TB, publishing purported proof such as internal documents, financial records, and scanned passports on its leak site.
Separate reporting described an unrelated cloud-focused cybercrime campaign attributed to TeamPCP (aka PCPcat / ShellForce), which has been compromising exposed and misconfigured cloud management interfaces at scale using automated, worm-like propagation. The activity was assessed as leveraging broad scanning and “industrialized” use of known weaknesses and misconfigurations (rather than novel exploits) to hijack infrastructure and monetize access, with claims of at least ~60,000 servers compromised globally since late December.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
After confirming the breach, Conpet said data had been exfiltrated but the volume was still under investigation. It warned that leaked personal and financial information could be abused for fraud and urged people to verify suspicious requests through official channels.
Conpet said it was hit by a Qilin ransomware attack the previous week that compromised its corporate IT infrastructure. The company stated that pipeline operations were unaffected and that it was investigating with Romania's National Cyber Security Directorate.
The Russia-based Qilin ransomware group claimed it had exfiltrated nearly 1 TB of data from Conpet and posted sample documents to support the claim.
SafePay claimed responsibility for a ransomware attack against Conduent and alleged that it stole 8.5 TB of data from the company.
German authorities warned about phishing messages impersonating 'Signal Support' that attempt to trick targets into sharing SMS PIN or verification codes for Signal accounts.
The U.S. Cybersecurity Information Sharing Act of 2015 was reauthorized through September 30, 2026 via the Consolidated Appropriations Act, 2026, preserving liability protections for certain cyber information sharing.
Talos-linked reporting said the DKnife toolkit has been used since 2019 to compromise routers and hijack software downloads and updates, delivering ShadowPad and DarkNimbus malware. The activity was assessed with high confidence as China-nexus.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourceresearch.checkpoint.com
Open sourcesherpaintelligence.substack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.