Security

Major energy contractor reports 'limited' access to IT after ransomware locks files

ENGlobal customers include the Pentagon as well as major oil and gas producers


American energy contractor ENGlobal disclosed that access to its IT systems remains limited following a ransomware infection in late November.

In a Monday filing with the US Securities and Exchange Commission (SEC), the company said it became aware of a cybersecurity incident on November 25 after criminals broke into its networks and locked up some of its files. 

"While the investigation and remediation efforts remain ongoing, access to the company's IT system is limited to essential business operations," according to the Form 8-K filing.

The Form 8-K filing doesn't specify how much and what type of data the crooks got their hands on, stating only that an investigation revealed they had "illegally accessed the company's IT system and encrypted some of its data files," but it's worth noting that ENGlobal has several high profile customers including the US Department of Defense and Department of Energy, as well as private companies that produce fuel and gas. 

ENGlobal provides engineering, automation, and construction services for these critical infrastructure sectors. This makes it a high value target for extortionists, both for the sensitive information it houses and also because digital crooks know that major corporations providing critical services are more likely to pay a ransom demand to keep their operations up and running and to protect their customers' data.

ENGlobal did not immediately respond to The Register's inquiries about the attack. 

Upon detecting the intruders, the company says it "immediately took steps to contain, assess and remediate the cybersecurity incident, including beginning an internal investigation, engaging external cybersecurity specialists, and restricting access to its IT system."

There's no word yet on when ENGlobal expects to restore full access to these systems, and it hasn't determined if the ransomware attack will have any material impact on its finances or hurt its operations.

ENGlobal reported $39 million in revenue last year.

This latest cybercrime comes as critical orgs across the US and the UK have come under increasing attack from online gangs.

Late last month a ransomware crew threatened to leak data stolen from one of England's top children's hospitals: Liverpool's Alder Hey Children's Hospital and Liverpool Heart and Chest Hospital NHS Foundation Trust.

In October, American Water stopped issuing bills and took its MyWater app offline while it investigated a cyberattack on its systems. The major provider supplies water to over 14 million people in the US and numerous military bases. ®

Send us news
11 Comments

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

'Codefinger' crims on the hunt for compromised keys

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

3 CVEs added to CISA's catalog

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Gee, wonder why Beijing is so keen on the – checks notes – Committee on Foreign Investment in the US

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed

Here's what $20 gets you these days

Russia's Star Blizzard phishing crew caught targeting WhatsApp accounts

FSB cyberspies venture into a new app for espionage, Microsoft says

China's Salt Typhoon spies spotted on US govt networks before telcos, CISA boss says

We are only seeing 'the tip of the iceberg,' Easterly warns

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America

Hey, Xi: Zài jiàn!

Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI

Scumbags stole API keys, then started a hacking-as-a-service biz, it is claimed

FireScam infostealer poses as Telegram Premium app to surveil Android devices

Once installed, it helps itself to your data like it's a free buffet

Charter, Consolidated, Windstream reportedly join China's Salt Typhoon victim list

Slow drip of compromised telecom networks continues

Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid

OFAC, Office of the Treasury Secretary feared hit in data-snarfing swoop