ALPHV claimed a data theft at Canada's Trans-Northern Pipelines
- Organization
- Trans-Northern Pipelines
- Exploit
- Hacking
- Industry
- Energy
The ALPHV/BlackCat ransomware group listed Trans-Northern Pipelines on its extortion site on February 13, 2024, claiming it had stolen a large volume of internal data from the Canadian fuel pipeline operator. Reports of the volume differed: The Register cited the gang's claim of 190 GB, while Cybersecurity Dive reported 183 GB.
Trans-Northern confirmed that it had experienced a cybersecurity incident in November 2023 that affected a limited number of internal computer systems. A spokesperson said the company brought in outside cybersecurity specialists, contained the incident, and continued to operate its pipelines safely throughout. The company said it was not aware of a ransom demand connected to the incident and that it was reviewing the claims posted on the dark web.
The disruption did have a regulatory consequence. Trans-Northern told the Canada Energy Regulator that the attack had limited its ability to retrieve files and exchange data electronically, delaying its response to the regulator's questions about unauthorized ground activity near one of its pipelines.
Trans-Northern operates roughly 850 kilometres of pipeline across Ontario and Quebec and about 320 kilometres in Alberta, moving around 221,300 barrels of refined products a day, including gasoline, diesel, aviation fuel and heating fuel.
Two days after the listing appeared, the U.S. State Department announced rewards of up to $15 million for information on ALPHV/BlackCat leaders and affiliates.