Executive Summary
In early February 2026, Conpet, Romania's national oil pipeline operator, experienced a cyberattack that disrupted its corporate IT infrastructure and rendered its website inaccessible. The Qilin ransomware group claimed responsibility, alleging the theft of nearly 1TB of sensitive documents, including financial records and personal identification data. Despite these disruptions, Conpet's operational technologies, such as the SCADA and telecommunications systems, remained unaffected, ensuring uninterrupted crude oil and gasoline transportation services. This incident underscores the escalating threat posed by ransomware groups like Qilin, which have increasingly targeted critical infrastructure sectors worldwide. Organizations must bolster their cybersecurity defenses to mitigate the risks associated with such sophisticated attacks.
Why This Matters Now
The Qilin ransomware group's attack on Conpet highlights the growing trend of cybercriminals targeting critical infrastructure, emphasizing the urgent need for enhanced cybersecurity measures in essential service sectors.
Attack Path Analysis
The Qilin ransomware group gained initial access to Conpet's corporate IT infrastructure, likely through phishing emails or exploiting vulnerabilities in public-facing applications. Once inside, they escalated privileges by harvesting credentials and exploiting misconfigurations, enabling them to move laterally across the network. They established command and control channels to maintain persistence and exfiltrated nearly 1TB of sensitive data. Finally, they encrypted critical business systems, disrupting operations and taking down the company's website.
Kill Chain Progression
Initial Compromise
Description
The attackers likely gained initial access through phishing emails containing malicious links or attachments, or by exploiting vulnerabilities in public-facing applications.
Related CVEs
CVE-2024-21762
CVSS 9.8An out-of-bounds write vulnerability in Fortinet FortiOS allows remote attackers to execute arbitrary code via specially crafted requests.
Affected Products:
Fortinet FortiOS – < 7.0.12, < 7.2.5
Exploit Status:
exploited in the wildCVE-2024-55591
CVSS 9.8An authentication bypass vulnerability in Fortinet FortiOS allows unauthenticated attackers to gain administrative access to the system.
Affected Products:
Fortinet FortiOS – < 7.0.12, < 7.2.5
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Phishing
Data Encrypted for Impact
Obfuscated Files or Information
Exfiltration Over C2 Channel
Inhibit System Recovery
Application Layer Protocol
Command and Scripting Interpreter
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – ICT Risk Management Framework
Control ID: Article 5
PCI DSS 4.0 – Implement an Incident Response Plan
Control ID: Requirement 12.10
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: Section 500.15
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity Pillar
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical infrastructure ransomware attacks like Qilin targeting pipeline operators expose SCADA vulnerabilities requiring enhanced egress security and zero trust segmentation controls.
Utilities
Ransomware targeting operational technology systems demands improved east-west traffic security, encrypted communications, and multicloud visibility to prevent service disruption and data exfiltration.
Government Administration
National infrastructure cyberattacks involving DIICOT investigations highlight need for threat detection capabilities and secure hybrid connectivity across government cybersecurity coordination frameworks.
Computer/Network Security
Pipeline ransomware incidents demonstrate requirements for cloud native security fabric, inline IPS protection, and anomaly detection to defend critical infrastructure clients.
Sources
- Romanian oil pipeline operator Conpet discloses cyberattackhttps://www.bleepingcomputer.com/news/security/romanian-oil-pipeline-operator-conpet-discloses-cyberattack-qilin-ransomware/Verified
- Critical Fortinet flaws now exploited in Qilin ransomware attackshttps://www.bleepingcomputer.com/news/security/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/Verified
- Qilin ransomware escalates rapidly in 2025, targeting critical sectors with 700 attacks amid RansomHub shutdownhttps://industrialcyber.co/ransomware/qilin-ransomware-escalates-rapidly-in-2025-targeting-critical-sectors-with-700-attacks-amid-ransomhub-shutdown/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF could have significantly constrained the Qilin ransomware group's ability to escalate privileges, move laterally, and exfiltrate data within Conpet's network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Aviatrix CNSF may have limited the attacker's initial access by enforcing identity-aware policies and segmenting public-facing applications, reducing the exposure of vulnerable services.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely have constrained the attacker's ability to escalate privileges by enforcing least-privilege access controls and limiting access to critical systems.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security may have limited lateral movement by monitoring and controlling internal traffic, reducing the attacker's ability to traverse the network.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely have constrained the establishment of command and control channels by providing real-time monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement may have limited data exfiltration by controlling outbound traffic and enforcing policies that restrict unauthorized data transfers.
While Aviatrix CNSF could have reduced the attacker's reach and constrained lateral movement, the encryption of critical systems indicates a need for comprehensive endpoint protection and data recovery strategies.
Impact at a Glance
Affected Business Functions
- Corporate IT Infrastructure
- Public Website
Estimated downtime: 3 days
Estimated loss: $500,000
Approximately 1TB of internal documents, including financial information and passport scans.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and enforce least privilege access controls.
- • Deploy East-West Traffic Security measures to monitor and control internal network communications, detecting unauthorized movements.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block connections to malicious external servers.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Establish Multicloud Visibility & Control to maintain comprehensive oversight of all cloud environments and detect potential threats.



