State oil company Saudi Aramco was hit by destructive malware, later known as Shamoon, which wiped data on around 30,000 of its workstations. A group calling itself the Cutting Sword of Justice claimed responsibility.
What happened
- The attack began on 15 August 2012 and affected around three-quarters of the company’s workstations.
- The malware overwrote files and the disks’ master boot records, leaving computers unusable; the company took its network offline to contain it.
- Aramco said exploration, production, and other core operational systems were not affected because they ran on isolated networks.
- US officials and researchers later linked the attack to Iran; Iran denied involvement.
Why it mattered
Shamoon was among the most destructive cyber attacks on a company at the time and showed how wiper malware could cripple corporate IT on a massive scale. Variants of Shamoon reappeared in attacks in the Gulf in 2016 and 2018.
Lessons for organisations
Keep offline or immutable backups and test rebuilding systems at scale. Segregating operational networks from corporate IT, as Aramco did, can limit the damage. Restrict privileged accounts, which wiper attacks commonly abuse to spread.
Sources: Dark Reading, CCDCOE Cyber Law Toolkit
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.