Pakistan Petroleum Limited Reports Cybersecurity Incident Involving Ransomware Attack

Karachi: Pakistan Petroleum Limited (PPL) has reported a cybersecurity incident involving a ransomware attack that was detected on August 6, 2025. In response to the intrusion, PPL's cybersecurity protocols were immediately activated, according to a statement released by the company.

The incident targeted parts of PPL's IT infrastructure, prompting the company's IT and cybersecurity teams, along with external experts, to implement containment measures. These measures included the temporary suspension of selected non-critical IT services as a precautionary step to minimize potential damage and maintain the integrity of the systems.

PPL has stated that its multi-layered cybersecurity framework enabled the rapid isolation of the threat. Importantly, there is no evidence to suggest that business-critical or sensitive data was compromised, and core operational systems remain unaffected.

Reports circulated on social media contained inaccuracies regarding the incident. PPL confirmed that a ransomware note was received from an external actor, and in compliance with legal requirements, the incident was reported to relevant law enforcement and regulatory authorities. Investigations are ongoing, with no contact made with the hackers. Financial transactions were conducted manually to ensure system security during a comprehensive scan.

According to information available from the Pakistan Stock Exchange (PSX), PPL's shares experienced a Minor move in the wake of the incident. The company, which is part of the designated market category of oil and gas, has emphasized its commitment to transparency and is undertaking a forensic analysis to enhance its cyber defenses.

PPL is working to restore full system functionality securely and methodically, prioritizing the protection of its digital infrastructure. The company remains focused on maintaining stakeholder trust through timely action and proactive cyber risk management.