Netfilim Ransomware Operators Publishes the Data Leak Part 2 of W&T Offshore, a Leading Independent Oil and Natural Gas Producer

Once again, the Netfilim ransomware operators leaked sensitive and confidential files of the W&T Offshore Inc. Earlier to this, they published the data leak part 1 of the company on 27 April 2020, which was verified and been reported by the Cyble Research Team.

W&T Offshore has been an independent oil and natural gas producer active in the acquisition, exploration, and development of properties in the Gulf of Mexico since 1983. For the past 36 + years, we have successfully discovered and produced properties on the conventional shelf and in the deepwater across the Gulf of Mexico thanks to the significant technical expertise of our Founder and CEO, Tracy Krohn, and the team he has assembled. They began trading on the NYSE under ticker symbol “WTI” in 2005 and our headquarters is in Houston, Texas.

Once again, the Cyble Research Team has verified the data leak, which consists of around 4 GB of sensitive and financial data such as organization’s tax return documents, quarterly tax provision documents, partnership agreements, Audit reports, and many more.  As per Cyble’s researchers, the Netfilim ransomware operators have made this data leak due to the W&T Offshore not taking the previous leak seriously. Below are the snapshots of the data being leaked by the ransomware operators-:

Snapshot of Message been posted by the Ransomware Operators

Snapshot of few of the files from the directory listing being leaked by Netfilim 

Update: On June 3, 2020, the group leaked part 3 of their leak (around 5GB) as below:

About Cyble:

Cyble Inc.’s mission is to provide organizations with a real-time view of their supply chain cyber threats and risks. Their SaaS-based solution powered by machine learning and human analysis provides organizations’ insights to cyber threats introduced by suppliers and enables them to respond to them faster and more efficiently.

Cyble strives to be a reliable partner/facilitator to its clients allowing them with unprecedented security scoring of suppliers through cyber intelligence sourced from open and closed channels such as OSINT, the dark web and deep web monitoring and passive scanning of internet presence. Furthermore, the intelligence clubbed with machine learning capabilities fused with human analysis also allows clients to gain real-time cyber threat intel and help build better and stronger resilience to cyber breaches and hacks. Due to the nature of the collected data, the company also offer threat intelligence capabilities out-of-box to their subscribers.