← Saipem

2018 Saipem — Shamoon variant destructive attack on Middle East, India, and Aberdeen servers

2018 Unknown records affected Share on X

Data compromised

High-volume operational filesystem destruction—public sources highlighted availability and intellectual-property risk more than PII row counts

Technical writeup

Italian oilfield contractor Saipem publicly acknowledged a December 2018 incident that disabled hundreds of Windows servers using a Shamoon-style wiper focused on MBR and mass data overwrite, concentrated in Saudi Arabia, the UAE, Kuwait, India, and Scotland while core Italy operations largely continued. Insurer and trade coverage linked tactics to earlier Aramco-era Shamoon campaigns, whereas Saipem emphasized forensic recovery from backups.

Root cause

Privileged-access deployment of destructive wiper malware (Shamoon-class Disttrack variant per Unit 42)

References