The IT Army of Ukraine asserts that it broke into the Russian oil company Gazprom's network and gained access to a 1.5 GB archive.
The hacktivist collective claimed that the cache contained more than 6,000 data from the Gazprom group companies when they disclosed the hack on their Telegram channel.
The Koviktinsky well's archive includes data on financial and economic operations, testing and drilling reports, as well as the implementation and adjustment of automated systems.
They were able to create a hack of the pipeline's pressurization controls as a result of the breach, which led to a pipeline rupture and subsequent fire.
Source: https://securityaffairs.com/141640/hacktivism/it-army-of-ukraine-hacked-gazprom.html
TPRM report: https://scoringcyber.rankiteo.com/company/gazprom
"id": "gaz201781023",
"linkid": "gazprom",
"type": "Breach",
"date": "01/2023",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'Oil and Gas',
'location': 'Russia',
'name': 'Gazprom',
'type': 'Corporation'}],
'attack_vector': 'Network Intrusion',
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': 'More than 6,000',
'type_of_data_compromised': ['Financial and economic '
'operations data',
'Testing and drilling reports',
'Automated systems '
'implementation and adjustment '
'data']},
'description': 'The IT Army of Ukraine asserts that it broke into the Russian '
"oil company Gazprom's network and gained access to a 1.5 GB "
'archive. The hacktivist collective claimed that the cache '
'contained more than 6,000 data from the Gazprom group '
'companies when they disclosed the hack on their Telegram '
"channel. The Koviktinsky well's archive includes data on "
'financial and economic operations, testing and drilling '
'reports, as well as the implementation and adjustment of '
'automated systems. They were able to create a hack of the '
"pipeline's pressurization controls as a result of the breach, "
'which led to a pipeline rupture and subsequent fire.',
'impact': {'data_compromised': ['Financial and economic operations data',
'Testing and drilling reports',
'Automated systems implementation and '
'adjustment data'],
'operational_impact': 'Pipeline rupture and subsequent fire',
'systems_affected': ["Pipeline's pressurization controls"]},
'motivation': 'Political',
'references': [{'source': 'IT Army of Ukraine Telegram Channel'}],
'threat_actor': 'IT Army of Ukraine',
'title': 'Gazprom Network Breach and Pipeline Rupture',
'type': 'Hacktivism'}