Nestoil listed by the blacksuit ransomware group
Nestoil
Overview
On 6 May 2024, the BlackSuit ransomware group listed Nestoil on its leak site. Nestoil is a Nigerian oil and gas services company, part of the Nestoil group active in engineering, procurement and construction for the energy sector. The listing identified the company as a victim.
What was published
The BlackSuit listing for Nestoil did not include a record count or a data inventory. BlackSuit has released stolen files for other victims following its disclosure format. No archive linked to Nestoil was observed during the analysis window.
Risks for affected individuals
Nestoil employees and its partners in the energy sector could be exposed if personnel records, project documentation or financial data were stolen. Energy industry documents can support targeted attacks on project infrastructure and impersonation of company officials.
What remains unknown
The categories and volume of stolen data, and whether BlackSuit published files, are not confirmed. No official statement from Nestoil about the incident has been identified.
What affected people should do
Employees should change passwords and enable multi-factor authentication on business accounts. Partners and contractors should verify payment and project communications through official channels and report any suspicious messages.
Sources
- http://weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion/?id=3eO36XPLsUprFcaz