Romania’s Oltenia Energy Complex suffers major ransomware attack
嗯,用户让我总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。首先,我需要仔细阅读文章,抓住主要信息。 文章讲的是罗马尼亚的Oltenia Energy Complex遭受了勒索软件攻击,导致IT系统瘫痪。时间是12月26日,攻击类型是Gentlemen ransomware。这次攻击影响了ERP、邮件和网站等系统,但国家能源供应没有受到影响。公司已经隔离了受影响的系统,并通知了相关部门。现在正在从备份恢复服务,并调查事件范围和数据泄露情况。 用户的需求是用中文简洁地总结内容,不超过100字。我需要提取关键点:事件发生的时间、地点、攻击类型、影响范围以及公司的应对措施。 可能的结构是:时间+地点+事件+影响+应对措施。这样既简洁又全面。 现在试着组织语言:罗马尼亚最大燃煤电厂Oltenia Energy Complex于12月26日遭遇Gentlemen勒索软件攻击,导致IT系统瘫痪,包括ERP、邮件和网站。虽然部分运营受影响,但国家能源供应未受威胁。公司已隔离系统并通知相关部门,正在从备份恢复服务,并调查事件范围和数据泄露情况。 检查一下字数是否在100字以内,大约97字左右,符合要求。 </think> 罗马尼亚最大燃煤电厂Oltenia Energy Complex于12月26日遭遇Gentlemen勒索软件攻击,导致IT系统瘫痪,包括ERP、邮件和网站。虽然部分运营受影响,但国家能源供应未受威胁。公司已隔离系统并通知相关部门,正在从备份恢复服务,并调查事件范围和数据泄露情况。 2025-12-29 21:30:44 Author: securityaffairs.com(查看原文) 阅读量:0 收藏

Romania’s Oltenia Energy Complex suffers major ransomware attack

Pierluigi Paganini December 29, 2025

A ransomware attack hit Romania’s Oltenia Energy Complex on December 26, knocking out IT systems at the country’s largest coal power producer.

A ransomware attack disrupted Oltenia Energy Complex, Romania’s largest coal-based power producer, shutting down its IT systems on December 26.

The Oltenia Energy Complex (CE Oltenia) is Romania’s leading state-controlled lignite mining and coal-fired power producer, operating 12 units with 3,570 MW capacity across Rovinari, Turceni, and Craiova plants, plus 15 open-pit mines yielding ~15-18 Mt annually. It employs around 10,000 workers (down from 15,000), serves wholesale/retail electricity markets (est. hundreds of thousands to low millions of customers), and generated ~€940M revenue in 2017 with recent profitability amid restructuring. Facing EU green transition, it invests €1.4B in PV and gas, ensuring baseload security.

On December 26, 2025, the company detected a Gentlemen ransomware attack that encrypted documents and disrupted key IT systems, including ERP, email and the website. Operations were partially affected, but the Romanian energy provider highlighted that the national energy supply remained safe. Oltenia Energy Complex isolated the impacted systems and notified the relevant authorities, including the National Directorate of Cyber Security, the Ministry of Energy

IT teams began restoring services from backups on new infrastructure, while the scope of the incident and any data leak are still under investigation.

“On December 26, 2025, around 01:40, a ransomware type computer attack, called “Gentlemen”, was identified, which affected the IT business infrastructure of the Oltenia Energy Complex Society.” reads the statement published by the company.

“Following the attack, some documents and files have been encrypted, and several computer applications have become temporarily unavailable, including ERP systems, document management applications, email service and the company website. The company’s activity was partially affected, without endangering the functioning of the National Energy System.”

The company is investigating the incident to determine the scope and the exact extent of the security breach. It’s unclear if threat actors have stolen data from the Oltenia Energy Complex.

The company also filed a criminal complaint with DIICOT (Directorate for Investigating Organized Crime and Terrorism)

​At the time of this writing, the Gentlemen ransomware group has yet to add the Romanian energy firm to its Tor data leak site, a circumstance that suggests an ongoing negotiation.

Recently, Romanian Waters (Administrația Națională Apele Române), the country’s water management authority, suffered a ransomware attack.

According to the National Cyber Security Directorate (DNSC), the incident affected around 1,000 computer systems across the central organization and 10 of its 11 regional offices. The attack disrupted IT assets, including GIS servers, databases, email and web services, Windows workstations, and domain name servers.

Authorities stressed that operational technology (OT) systems managing water infrastructure were not impacted, and water operations continue to function normally.

Government experts who are investigating the incident confirmed that threat actors used Windows BitLocker to encrypt systems and issued a ransom note demanding contact within seven days. However, at this time, the attack vector has not yet been identified.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Oltenia Energy Complex)




文章来源: https://securityaffairs.com/186290/cyber-crime/romanias-oltenia-energy-complex-suffers-major-ransomware-attack.html
如有侵权请联系:admin#unsafe.sh