Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Insiders suspected in Saudi cyber attack
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Insiders suspected in Saudi cyber attack

Insiders suspected in Saudi cyber attack

fptechno • September 7, 2012, 16:42:41 IST
Whatsapp Facebook Twitter

One or more insiders with high-level access are suspected of assisting the hackers who damaged some 30,000 computers at Saudi Arabia’s …

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Insiders suspected in Saudi cyber attack

One or more insiders with high-level access are suspected of assisting the hackers who damaged some 30,000 computers at Saudi Arabia’s national oil company last month, sources familiar with the company’s investigation say.

The attack using a computer virus known as Shamoon against Saudi Aramco - the world’s biggest oil company - is one of the most destructive cyber strikes conducted against a single business.

Shamoon spread through the company’s network and wiped computers’ hard drives clean. Saudi Aramco says damage was limited to office computers and did not affect systems software that might hurt technical operations.

STORY CONTINUES BELOW THIS AD

A new line of attack. Image Source

Could be an inside job

The hackers’ apparent access to a mole, willing to take personal risk to help, is an extraordinary development in a country where open dissent is banned.

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

“It was someone who had inside knowledge and inside privileges within the company,” said a source familiar with the ongoing forensic examination.

Hackers from a group called “The Cutting Sword of Justice” claimed responsibility for the attack. They say the computer virus gave them access to documents from Aramco’s computers, and have threatened to release secrets. N o documents have so far been published.

Reports of similar attacks on other oil and gas firms in the Middle East, including in neighbouring Qatar, suggest there may be similar activity elsewhere in the region, although the attacks have not been linked.

Saudi Aramco declined to comment. “Saudi Aramco doesn’t comment on rumours and conjectures amidst an ongoing probe,” it said.

The hacking group that claimed responsibility for the attack described its motives as political.

In a posting on an online bulletin board the day the files were wiped, the group said Saudi Aramco was the main source of income for the Saudi government, which it blamed for “crimes and atrocities” in several countries, including Syria and Bahrain.

STORY CONTINUES BELOW THIS AD

The Saudi interior ministry did not respond to requests for comment. The foreign ministry was not available for comment.

Saudi Arabia sent troops into Bahrain last year to back the Gulf state’s rulers, fellow Sunni Muslims, against Shi’ite-led protesters. Riyadh is also sympathetic to mainly Sunni rebels in Syria.

Saudi Arabia’s economy is heavily dependent on oil. Oil export revenues have accounted for 80-90 percent of total Saudi revenues and above 40 percent of the country’s gross domestic product, according to U.S. data.

DESTRUCTIVE

Saudi Aramco, which supplies about a tenth of the world’s oil, has hired at least six firms with expertise in hacking attacks, bringing in dozens of outside experts to investigate the attack and repair computers, the sources say.

According to analysis of Shamoon by computer security firm Symantec, the way the virus gets into networks may vary, but once inside it tries to infect every computer in the local area network before erasing files to render PCs useless.

STORY CONTINUES BELOW THIS AD

“We don’t normally see threats that are so destructive,” Liam O Murchu, who helped lead Symantec’s research into the virus, said. “It’s probably been 10 years since we saw something so destructive.”

The state-run oil company - whose 260 billion barrels of crude oil alone would value it at over 8 trillion dollars, or 14 times the market value of Apple Inc. - was well protected against break-in attempts over the Internet, according to people familiar with its network operations.

Yet those sources say such protections could not prevent an attack by an insider with high-level access.

It is unusual for insiders to be fingered in cyber attacks. Verizon Business, which publishes the most comprehensive annual survey of data breaches, said that insiders were implicated in just 4 percent of cases last year.

The hackers behind the Shamoon attack siphoned off data from a relatively small number of computers, delivering it to a remote server, the sources said. They later threatened to release that information.

STORY CONTINUES BELOW THIS AD

Because the virus wiped the hard drives, it is difficult for Saudi Aramco to determine exactly what information the hackers obtained.

An email address and password, which the poster claimed belonged to Aramco CEO Khalid Al-Falih, was posted on a website often used by hackers to show off their achievements, this time signed by the “Angry Internet Lovers”. No sensitive Aramco files have been uploaded on that site.

Sources who spoke to Reuters said they were not aware whether the hackers had made specific demands, what they might have been or whether they were met.

The sources would not say whether the suspected mole or moles are Saudi Aramco employees or outside contractors, or whether they accessed a workstation inside Saudi Aramco’s offices or accessed the network remotely.

The Saudi interior ministry was unavailable to comment on whether anyone has been arrested as part of the investigation.

VIRUS TARGETS PCS

The Shamoon virus is designed to attack ordinary business computers. It does not belong to the category of sophisticated cyber warfare tools - like the Stuxnet virus that attacked Iran’s nuclear programme in 2010 - which target industrial control systems and can paralyse critical infrastructure.

STORY CONTINUES BELOW THIS AD

“Based on initial reporting and analysis of the malware, no evidence exists that Shamoon specifically targets industrial control systems components or U.S. government agencies,” the Department of Homeland Security’s United States Computer Emergency Readiness Team said in an August 29 advisory.

Saudi Aramco has said that only office PCs running Microsoft Windows were damaged. Its oil exploration, production, export, sales and database systems all remained intact as they ran on isolated and heavily protected systems.

“All our core operations continued smoothly,” CEO Khalid Al-Falih told Saudi government and business officials at a security workshop on Wednesday.

“Not a single drop of oil was lost. No critical service or business transaction was directly impacted by the virus.”

It is standard industry practice to shield plant operating networks from hackers by running them on separate operating systems that are protected from the Internet.

Qatar’s natural gas firm Rasgas was also hit by a cyber attack last week, although it has not said how much damage was caused or whether Shamoon was the virus involved. Qatar, also a Sunni Gulf kingdom, has similar foes to Saudi Arabia.

STORY CONTINUES BELOW THIS AD

Its parent firm Qatar Petroleum, which also owns Qatar’s other main natural gas firm Qatargas, said it was unaffected but implied that other companies had been hit.

“Qatar Petroleum has not been affected by the computer virus that hit several oil and gas firms. All QP operations are continuing as normal,” it said in an official tweet on Monday.

Reuters

Tags
Computer virus General Symantec Virus ARAMCO Saudi Aramco Gulf computer attacks RasGas infection RasGas virus Saudi Aramco Virus virus attacks Aramco virus Saudi Arabia national oil company Saudi Arabia virusAramco virus suspect
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV