Kazakh oil giant denies cyberattack, says incident was 'planned' phishing drill
哈萨克斯坦国家石油公司否认印度网络安全公司Seqrite指控其成为新俄罗斯相关黑客组织目标,称事件为内部钓鱼演练。Seqrite报告称该组织自4月起活跃于中亚能源领域,并于5月入侵KazMunayGas员工邮箱发送恶意邮件。但KazMunayGas表示该活动为计划内信息安全测试,并提供证据支持。双方各执一词。 2025-9-8 17:15:44 Author: therecord.media(查看原文) 阅读量:9 收藏

Kazakhstan’s state oil company has dismissed claims by Indian cybersecurity firm Seqrite that it was the target of a new Russian-linked hacking group, saying the incident was in fact an internal phishing drill.

Seqrite Labs last week published research on what it called a newly identified group, NoisyBear, which it said had been active since April and focused on Central Asia’s energy sector. The company said NoisyBear compromised a KazMunayGas finance employee’s mailbox in May and used it to send phishing emails disguised as corporate policy updates, salary adjustments and IT department notices. The messages carried malicious archive files designed to install further payloads.

Seqrite attributed the activity to Russia, citing the attackers’ use of the Russian language and infrastructure hosted by sanctioned provider Aeza Group, as well as similarities with previous campaigns linked to Moscow-based actors. Aeza was sanctioned by the U.S. Treasury in July for allegedly supporting ransomware operators and online narcotics markets.

But KazMunayGas rejected Seqrite’s conclusions. In comments to Kazakh outlet Orda, the company said the incident was a scheduled simulation.

“In May 2025, KMG organized and carried out a planned internal exercise to test, assess, and improve employees’ awareness of information security,” the company said. It added that some of its employees were notified in advance, and the campaign was used to provide recommendations to staff.

Evidence in Seqrite’s own report appeared to support that claim: One screenshot of the phishing campaign showed test accounts among the recipients, such as addresses formatted as “test@kmg[.]kz., noted Russian cybersecurity expert Oleg Shakirov. Seqrite has not responded to Recorded Future News request for comments.

This is not the first case where an external security report has clashed with a company’s own account. In May, U.S. cloud storage firm Snowflake pushed back against allegations by cybersecurity company Hudson Rock that attackers had breached its systems in a high-profile incident tied to Ticketmaster and Santander Bank. Snowflake said no customer data was exposed, and the account cited by Hudson Rock belonged to a former employee’s demo environment.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/kazakstan-oil-company-kazmunaygas-phishing-simulation-not-cyberattack
如有侵权请联系:admin#unsafe.sh