Cyber Attackers Divert £700,000 Contract Payment from UK Oil and Gas Company

UK-listed oil and gas firm Zephyr Energy plc has confirmed it fell victim to a cyberattack that resulted in the loss of approximately £700,000 (nearly $1 million), after attackers successfully diverted a contractor payment into a fraudulent account.

The company disclosed the incident on April 9, revealing that one of its U.S.-based subsidiaries was targeted in what it described as a “highly sophisticated” business email compromise (BEC) scheme. The attack manipulated routine financial processes, allowing cybercriminals to reroute funds without immediate detection.

According to the firm, the fraudulent transaction occurred during a standard contractor payment cycle. The attackers, believed to have infiltrated or spoofed legitimate email communications, altered payment details so that the funds were transferred to an account under their control rather than the intended recipient.

Zephyr Energy, a technology-driven operator focused on oil and gas development in the Rocky Mountain region of the United States, said the breach was identified after the payment had already been completed. By that time, the money had been moved into a third-party account, complicating recovery efforts.

In response, the London-based company said it acted swiftly, alerting law enforcement authorities, engaging banking partners, and bringing in external cybersecurity specialists to trace and potentially recover the stolen funds. Investigations are ongoing.

The incident highlights the growing threat posed by business email compromise attacks, a form of cybercrime that relies on social engineering rather than malware. By impersonating trusted contacts or compromising legitimate email threads, attackers can trick organizations into authorizing fraudulent payments.

Cybersecurity experts warn that BEC attacks remain one of the most financially damaging forms of cybercrime globally, often targeting finance departments and exploiting gaps in payment verification procedures. The breach serves as another reminder that even established firms with international operations are not immune.

While the company has not disclosed whether any funds have been recovered so far, it emphasized that internal controls and payment verification processes are under review to prevent similar incidents in the future.

About The Author

Leave a Reply

Your email address will not be published. Required fields are marked *