Gentlemen Ransomware Strikes Romanian Energy Provider

▼ Summary
– Romania’s largest coal-based energy producer, Oltenia Energy Complex, suffered a ransomware attack on December 26th, which took down its IT infrastructure.
– The attack encrypted files and disrupted key applications, but did not jeopardize the operation of Romania’s National Energy System.
– The company is restoring systems from backups and assessing whether data was stolen, while cooperating with national authorities.
– The attack is attributed to the Gentlemen ransomware operation, which uses compromised credentials to gain access to victim networks.
– This incident follows other recent ransomware attacks on major Romanian entities, including the national water authority and a major electricity distributor.
A significant ransomware incident disrupted operations at the Oltenia Energy Complex, Romania’s primary coal-based electricity producer, during the recent holiday period. The attack, which occurred on December 26th, forced the shutdown of critical IT systems at the state-owned utility. The company, which supplies roughly 30% of the nation’s power and operates four major plants, confirmed that the cyber intrusion led to encrypted files and the temporary unavailability of key applications. These included enterprise resource planning software, email services, document management platforms, and the corporate website.
Company officials emphasized that while internal activities were partially affected, the assault did not compromise the stability of Romania’s National Energy System. Immediate efforts focused on restoring operations using existing backups, with IT personnel rebuilding compromised systems on new infrastructure. An investigation is ongoing to determine the full scope of the breach, including whether any data was exfiltrated prior to the encryption process. The incident has been formally reported to the National Cyber Security Directorate, the Ministry of Energy, and other relevant authorities. A criminal complaint was also filed with DIICOT, the national agency responsible for investigating organized crime and terrorism, which includes cyber offenses.
Security researchers attribute the attack to the Gentlemen ransomware operation, a group that first appeared in August. This gang typically gains initial network access by exploiting compromised credentials or targeting internet-exposed services. Upon encryption, they leave ransom notes titled “README-GENTLEMEN.txt” and append a unique .7mtzhh file extension to locked documents. The Gentlemen group maintains a dedicated leak site on the Tor network, where it has listed dozens of victims since its emergence. As of now, Oltenia Energy Complex has not been added to that site, suggesting potential ongoing negotiations between the attackers and the company.
This event is part of a concerning pattern of cyberattacks targeting critical infrastructure in Romania. Just two weeks prior, the country’s national water management authority, Romanian Waters, suffered a ransomware infection that impacted around 1,000 computer systems across most of its regional offices. Fortunately, core operations relying on telephone and radio dispatch centers remained functional. Other major incidents in recent years include a breach of the Electrica Group by the Lynx ransomware gang in late 2023 and a widespread Backmydata ransomware attack in February 2024 that forced over 100 Romanian hospitals to take their healthcare management systems offline. These repeated attacks underscore the persistent threat ransomware poses to essential services and national security.
(Source: Bleeping Computer)