logo

Assessment of Ransomware Event at U.S. Pipeline Operator

ID: 7d24a0a8-67b8-5480-9a28-0c9a63319fae

STIX ID: report--7d24a0a8-67b8-5480-9a28-0c9a63319fae

Feed Name: Dragos Blog

Threat Score
75/100

Date Published: 2020-02-19

Date Updated: 2026-04-27

...
...

Dragos links a CISA alert to a December 2019 U.S. Coast Guard report describing a Ryuk ransomware incident at an unnamed U.S. pipeline operator's natural gas compression facility: attackers used a phishing link to breach the IT network, pivoted to Windows-based ICS devices (HMIs and historians) due to insufficient IT/OT segregation, encrypted systems and caused loss of view leading to a controlled shutdown and approximately two days of operational downtime; the report concludes the incident reflects commodity ransomware behavior rather than ICS-specific targeting and provides recommendations (phishing awareness, email flagging, stronger IT/OT segmentation, patching, backups, monitoring, and recovery testing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.