Hackers Demand $5 Million From Mexico's State Oil Firm in Ransomware Attack

The attack is the latest challenge for Pemex, which is battling to pay down heavy debts.

Advertisement
By Reuters | Updated: 13 November 2019 19:32 IST

Hackers demanded about $5 million (roughly Rs.36 crores ) in Bitcoin from Mexico's Pemex, they told Reuters on Tuesday, saying the state oil firm missed a special discount by not paying immediately after a cyberattack that fouled up the company's systems. The hack, which Pemex said it detected on Sunday, forced the company to shut down computers across Mexico, freezing systems such as payments, according to five employees and internal emails.

Hackers have increasingly targeted companies with malicious programs that can cripple systems overseeing everything from supply chains to manufacturing, removing them only after receiving substantial payments.

A ransom note that appeared on Pemex computers seen by Reuters pointed to a darknet website affiliated with "DoppelPaymer," a type of ransomware.

Advertisement

The website demanded 565 Bitcoins, or nearly $5 million at current prices, and threatened Pemex with a 48-hour deadline, listing an email address to contact.

Advertisement

When Reuters wrote to the email for details, the apparent hackers replied, saying that Pemex had missed a deadline for a "special price," an apparent reference to the discounts sometimes offered to ransomware victims for early payment. But they said Pemex still had time to meet their Bitcoin demand and would not comment further while the new deadline was pending.

Pemex did not immediately respond to a request for comment about the ransom demand.

Advertisement

The attack is the latest challenge for Pemex, which is battling to pay down heavy debts, reverse years of declining oil production and avoid downgrades to its credit ratings.

Pemex said its storage and distribution facilities were operating normally and that the attack had affected less than 5 percent of its computers.

Advertisement

"Let's avoid rumours and disinformation," it said in a statement.

A person who works in Pemex's production and exploration said that division was not affected.

There was some confusion about which form of ransomware was used in the attack. One Pemex official said in an internal email the company was targeted by "Ryuk," a strain of ransomware that experts say typically targets companies with annual revenue between $500 million and $1 billion - far below Pemex's levels.

DoppelPaymer is a relatively new breed of ransomware that cybersecurity firm CrowdStrike said was behind recent attacks on Chile's Agriculture Ministry and the town of Edcouch in Texas.

On Tuesday, Pemex was reconnecting unaffected computers to its network using software patches and wiping infected computers clean, said one source, who spoke on condition of anonymity.

The company had to communicate with employees via mobile messaging service WhatsApp because employees could not open their emails, said another source, who was also not authorised to speak to reporters.

"In finances, all the computers are off, there could eventually be problems with payments," the person said.

Companies taken hostage digitally can suffer catastrophic damage, whether or not they pay ransom.

Norwegian aluminum producer Norsk Hydro was hit in March by ransomware that spread to 160 sites, eventually forcing parts of the industrial giant to operate via pen and paper.

The company refused to pay the ransom. But it said the attack generated up to $71 million in cleanup costs - of which only $3.6 million so far had been paid out by insurance.

© Thomson Reuters 2019

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Further reading: Pemex, Mexico, DoppelPaymer, Ryuk
Advertisement
Popular Mobile Brands
  1. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  2. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  3. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  4. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  5. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  6. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  7. Just a Day After Releasing GPT-5.3 Instant, OpenAI Teases GPT-5.4 Model
  8. WhatsApp Plus Could Soon Let You Pay to Access These Features
  9. Nothing Launches Headphone (a) With Adaptive ANC, Spatial Audio Support
  10. Nothing Phone 4a Pro Teaser Hints at the Presence of This Phone 3 Feature
  1. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  2. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  3. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  4. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  5. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  6. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  7. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  8. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
  9. Nothing Phone 4a Launched in India With Glyph Bar Interface Alongside Nothing Phone 4a Pro: Price, Specs
  10. Oppo Find N6 Key Features, Colour Options Leaked Ahead of Imminent China Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.