2018 Saipem — Shamoon variant destructive attack on Middle East, India, and Aberdeen servers
Data compromised
High-volume operational filesystem destruction—public sources highlighted availability and intellectual-property risk more than PII row counts
Technical writeup
Italian oilfield contractor Saipem publicly acknowledged a December 2018 incident that disabled hundreds of Windows servers using a Shamoon-style wiper focused on MBR and mass data overwrite, concentrated in Saudi Arabia, the UAE, Kuwait, India, and Scotland while core Italy operations largely continued. Insurer and trade coverage linked tactics to earlier Aramco-era Shamoon campaigns, whereas Saipem emphasized forensic recovery from backups.
Root cause
Privileged-access deployment of destructive wiper malware (Shamoon-class Disttrack variant per Unit 42)