Zephyr Energy Loses £700K in Cyber Attack Targeting Contractor Payment
Severity: Medium (Score: 48.9)
Sources: Theregister, Ajbell, Scworld, Techcrunch, Lse
Summary
Zephyr Energy plc reported a cybersecurity incident involving the diversion of £700,000 from a contractor payment to a third-party account. The attack, described as 'highly sophisticated,' targeted one of its U.S. subsidiaries and involved the rerouting of a legitimate payment. Upon discovery, Zephyr promptly notified law enforcement and engaged banks and consultants to recover the funds. The company's IT systems were assessed, and it confirmed that operations remain normal and the incident is contained. Additional security measures have been implemented to prevent future occurrences. Despite the loss, Zephyr stated it has sufficient working capital to continue operations without impact. Key Points: • Zephyr Energy lost approximately £700,000 due to a sophisticated cyber attack. • The incident involved the rerouting of a legitimate contractor payment to an attacker-controlled account. • The company has engaged law enforcement and consultants to recover the diverted funds.
Key Entities
- Phishing (attack_type)
- Zephyr Energy (company)
- Zephyr Energy PLC (company)
- United States (country)
- Energy (industry)
- T1566 - Phishing (mitre_attack)