News: 1643730629

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cyberattacker hits German service station petrol terminal provider

(2022/02/01)


Two companies owned by Hamburg-based company fuel group Marquard & Bahls are battling cyberattackers, with loading and unloading systems at the German arm of petrol tank terminal provider Oiltanking affected.

[1]

Aerial view of Oiltanking's tank farm in the harbor of Hamburg, Germany (click to enlarge)

The company this afternoon confirmed to The Register that Oiltanking GmbH's terminals – which provide Shell service stations, among others – are "operating with limited capacity" and that Mabanaft GmbH had "declared force majeure for the majority of its inland supply activities in Germany."

Shell has additional providers, however, and said it had "diverted operations to other suppliers to minimise disruption."

Mabanaft describes itself as the "leading independent importer and wholesaler of petroleum products in Germany."

A spokesperson for Oiltanking and Mabenaft told El Reg in a statement:

On Saturday, January 29th 2022, Oiltanking GmbH Group and Mabanaft GmbH & Co. KG (Mabanaft) Group discovered we have been the victim of a cyber incident affecting our IT systems.

Upon learning of the incident, we immediately took steps to enhance the security of our systems and processes and launched an investigation into the matter.

We are working to solve this issue according to our contingency plans, as well as to understand the full scope of the incident. We are undertaking a thorough investigation, together with external specialists and are collaborating closely with the relevant authorities.

Marquard & Bahls owns a portfolio that includes three divisions: the larger Oiltanking GmbH Group – which the firm told us "continues to operate all terminals in all global markets"; Skytanking; and the Mabanaft division – which, confusingly, houses Oiltanking Deutschland GmbH – which operates all terminals in Germany and is not part of the Oiltanking GmbH Group.

According to IATA, Skytanking, which supplies on-airport jet fuel, "currently operates at 70 airports in Europe, South Africa and India refueling more than 1.5 million aircraft a year."

[2]

Oiltanking told The Reg that the "cyberincident" had only affected the two German companies.

[3]

[4]

The firms said they were "committed to resolving the issue and minimizing the impact as quickly and effectively as possible. We will be keeping our customers and partners informed and provide updates as soon as more information becomes available."

According to its [5]most recent annual report [PDF], for the year 2020 and filed in May 2021, parent firm Marquard & Bahls had a "satisfactory operational year in 2020", with revenues of €9.183bn and pre-tax earnings of €149m. "Tank storage logistics and energy trading achieved good results, while aviation fuelling suffered a massive revenue collapse due to COVID-related travel restrictions."

[6]

The report singled out Germany's "service station business for commercial motor transport" – which was "initially in decline at the start of the pandemic but "gradually recovered in the second quarter."

Big moves last year by M&B's flagship holding, Oiltanking, included [7]flogging off four European liquid storage terminals to Evos in Q4 2021 for an "undisclosed" amount as well as [8]inking a deal with Singaporean authorities in which it became a founding "shareholder" of Singapore Trade Data Exchange (SGTraDex), a public-private partnership "aimed at reshaping the local supply chain ecosystem through digitalization." SGTraDex was expected to launch in "early 2022."

Oiltanking says on its website that it owns and operates 45 terminals in 20 countries in the Americas, Europe, Middle East, Africa, and Asia Pacific including China and India. The company adds that it has an overall storage capacity of more than 18.5 million cubic metres.

[9]

As for the German companies, Oiltanking Deutschland GmbH and Mabanaft GmbH invoking "force majeure" – a contractual clause that frees the business from liabilities arising from its obligations to customers – it's unclear what the outcome will be. They will have to demonstrate that the attack is within the scope of their contractual provisions.

We have asked the firms which software and systems were affected. German newspaper [10]Der Speigel reported that because Oiltanking's loading and unloading systems are "essentially automated", the operation of the tanker trucks that supply some of the nation's petrol stations is only possible to a "limited extent manually."

[11]Hack on Saudi Aramco hit 30,000 workstations, oil firm admits

[12]UK mulls making MSPs subject to mandatory security standards where they provide critical infrastructure

[13]USA signs internet freedom and no-hack pact it's ignored since 2018

[14]Suex to be you: Feds sanction cryptocurrency exchange for handling payments from 8+ ransomware variants

[15]Unhappy customers and their own tricks used against them, REvil ransomware gang reportedly pulled offline by 'multi-country' operations

Several onlookers have speculated that the attack may be ransomware, although this has not been confirmed.

Around [16]nine months ago , the operators of the Colonial Pipeline – which stretches 5,500 miles between Texas and New York, and can carry up to 3 million barrels of fuel per day – reportedly paid $5m to regain access to their systems after they were struck by ransomware, said to have been the work of the [17]Darkside group .

Charles Carmakal, senior VP at cybersecurity firm Mandiant, which responded to the incident, [18]revealed in an interview a month later that crooks had accessed Colonial Pipeline's network though an old VPN and password believed to have fallen into the wrong hands via the dark web. ®

Get our [19]Tech Resources



[1] https://regmedia.co.uk/2022/02/01/shutterstock_1539632045.jpg

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YflnO7mYSCvTuBftLrofRAAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YflnO7mYSCvTuBftLrofRAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YflnO7mYSCvTuBftLrofRAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.marquard-bahls.com/fileadmin/content/global_content/downloads/annual-reports/Marquard-Bahls_Annual-Report-2020_EN_web.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YflnO7mYSCvTuBftLrofRAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.oiltanking.com/es/publicaciones/notas-de-prensa/detalles/article/oiltanking-announces-sale-of-four-european-terminals-to-evos.html

[8] https://www.oiltanking.com/en/news-info/press-releases/details/article/oiltanking-joins-forces-with-singapore-authorities-and-industry-partners-to-enhance-digitalization-i.html

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YflnO7mYSCvTuBftLrofRAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.spiegel.de/netzwelt/web/shell-und-co-betroffen-cyberangriff-auf-benzin-versorger-von-tankstellen-in-deutschland-a-5f4494a1-db24-4cca-820e-dea923ac66a9-amp

[11] https://www.theregister.com/2012/08/29/saudi_aramco_malware_attack_analysis/

[12] https://www.theregister.com/2022/01/20/uk_nis_regulations_msp_plans/

[13] https://www.theregister.com/2021/11/11/usa_supports_paris_call/

[14] https://www.theregister.com/2021/09/21/feds_sanction_suex/

[15] https://www.theregister.com/2021/10/22/revil_offline_again/

[16] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/

[17] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/

[18] https://www.theregister.com/2021/06/09/old_vpn_colonial_pipeline/

[19] https://whitepapers.theregister.com/



It's been said here before, but . . .

Scott Broukell

Is it really too much to ask, or even demand, that such companies (e.g. rather important infrastructure etc.), "took steps to enhance the security of our systems and processes" BEFORE such fecking attacks take place! I mean let's face it for several decades ahead global powers are going to be increasingly slugging it out in this manner!

Sounds expensive...

Korev

They might have to Shell out a lot

Re: Sounds expensive...

TaabuTheCat

"Sounds expensive..."

Silly rabbit, they declared "force majeure", the universal get-out-of-jail-free card baked into every contract. "All beyond our control gov, honest."

It's difficult to see the picture when you are inside the frame.