Cyberattack on fuel supplier causes supply chain disruption
What it means
MISP EudorIA ha pubblicato l'advisory "Cyberattack on fuel supplier causes supply chain disruption". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: Cyberattack on fuel supplier causes supply chain disruption. Report from - [URL rimossa] (1643987697) A cyberattack has disrupted the activities in @[tag](misp-galaxy:target-information="Germany") of fuel supplier Oiltanking Deutschland GmbH & Co. KG. The supplier is, among others, responsible for deliveries to the thousands of Shell and Aral gas stations in @[tag](misp-galaxy:target-information="Germany"). The Oiltanking division of Hamburg-based Marquard & Bahls owns and operates 45 terminals in 20 countries. As far as we know only German branches of the firm are affected by the attack. Distribution system blocked --------------------------- The main problem for the supplier is that the automated systems that take care of loading the supply trucks are disabled. The underlying problem is that these systems can’t be operated manually and the automated system stopped working due to the attack. The company is using alternative loading points to fill part of the need and Shell is re-routing oil supplies to other depots. Aral, the largest petrol station network in @[tag](misp-galaxy:target-information="Germany") with around 2,300 stations, has also started supplying its stations from alternative sources in light of the disturbance. Since there are a total of 26 similar companies in @[tag](misp-galaxy:target-information="Germany") and the disruption only blocks one specific part of the distribution chain, it seems unlikely that the consequenc
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:46
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 95
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 95Last sharing verification: 2026-09-26T09:31:28.992189+00:00
- MISP event
- cdc842aa-761d-48e2-9b97-c344bed8b3a8
- MITRE ATT&CK
- Local Accounts - T1078.003, Disable or Modify Tools - T1562.001, File Deletion - T1070.004, OS Credential Dumping - T1003, Credentials from Web Browsers - T1555.003, Exfiltration to Cloud Storage - T1567.002, Exfiltration Over Asymmetric Encrypted Non-C2 Protocol - T1048.002, Data Encrypted for Impact - T1486, Inhibit System Recovery - T1490, Service Stop - T1489, Multi-hop Proxy - T1090.003, Lateral Tool Transfer - T1570, Process Discovery - T1057, File and Directory Discovery - T1083
- Classification
- High