2012 Saudi Aramco — Shamoon wiper destroyed ~tens of thousands of business PCs; oil production physically isolated (Aug)
Data compromised
Business records on wiped PCs; espionage vs pure destruction focus varies by victim segment—no consolidated PII census
Technical writeup
On August 15, 2012, destructive Shamoon malware triggered across Saudi Aramco’s conventional corporate Windows estate—wiping disks and replacing displays with a protest image while attackers calling themselves “Cutting Sword of Justice” took credit on Pastebin-style channels. The Council on Foreign Relations cyber tracker summarizes investigators’ view that tens of thousands of workstations were rendered unusable, pushing a recovery that included mass hardware replacement, while ICS segments feeding physical output were logically separated and oil flows reportedly continued. Kaspersky’s Securelist contemporaneously analyzed the Shamoon EraseMBR module family tying the wave to highly targeted wiper tradecraft rather than commodity ransomware.
Root cause
Insider-assisted or long-dwell intrusion culminating in coordinated wiper deployment across flat enterprise Windows networks (exact ingress debated in primary journalism)