Don’t do SECURITY. Do business SECURELY.

Shamoon malware wipes around 30,000 Saudi Aramco computers

Destructive Shamoon malware erased data on around 30,000 workstations at Saudi Aramco, one of the world's largest oil producers.

State oil company Saudi Aramco was hit by destructive malware, later known as Shamoon, which wiped data on around 30,000 of its workstations. A group calling itself the Cutting Sword of Justice claimed responsibility.

What happened

  • The attack began on 15 August 2012 and affected around three-quarters of the company’s workstations.
  • The malware overwrote files and the disks’ master boot records, leaving computers unusable; the company took its network offline to contain it.
  • Aramco said exploration, production, and other core operational systems were not affected because they ran on isolated networks.
  • US officials and researchers later linked the attack to Iran; Iran denied involvement.

Why it mattered

Shamoon was among the most destructive cyber attacks on a company at the time and showed how wiper malware could cripple corporate IT on a massive scale. Variants of Shamoon reappeared in attacks in the Gulf in 2016 and 2018.

Lessons for organisations

Keep offline or immutable backups and test rebuilding systems at scale. Segregating operational networks from corporate IT, as Aramco did, can limit the damage. Restrict privileged accounts, which wiper attacks commonly abuse to spread.

Sources: Dark Reading, CCDCOE Cyber Law Toolkit

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights