Israel’s largest oil refinery website offline after DDoS attack

Share:

Website of Israel’s largest oil refinery operator, BAZAN Group is inaccessible from most parts of the world as threat actors claim to have hacked the Group’s cyber systems.

The Haifa Bay-based BAZAN Group, formerly Oil Refineries Ltd., generates over $13.5 billion in annual revenue and employs more than 1,800 people.

The company boasts to have a total oil refining capacity of about 9.8 million tons of crude oil per year.

BAZAN website cut off from the internet

Over the weekend, incoming traffic to BAZAN Group’s websites, bazan.co.il and eng.bazan.co.il is either timing out, with HTTP 502 errors, or being refused by the company’s servers.

BleepingComputer confirmed that the oil refinery’s website has been made inaccessible for most visitors from around the world.

In our tests, the website was, however accessible from within Israel, possibly after imposition of a geo-block by BAZAN in an attempt to thwart an ongoing cyber attack.

Bazan Group website shows forbidden (HTTP 403) error message
Bazan Group website shows an ‘Access Denied’ error message
(BleepingComputer)

Cyber Avengers claims responsibility

In a Telegram channel, Iranian hacktivist group, ‘Cyber Avengers’ aka ‘CyberAv3ngers’ claimed that it had breached BAZAN’s network over the weekend.

On Saturday evening, the group additionally leaked what appeared to be screenshots of BAZAN’s SCADA systems, which are software applications used to monitor and operate industrial control systems.

These included diagrams of “Flare Gas Recovery Unit,” “Amine Regeneration” system, a petrochemical “Splitter Section,” and PLC code, as seen by BleepingComputer.

In a statement to BleepingComputer, published below, a spokesperson for BAZAN has dismissed the leaked materials as “entirely fabricated.”

“We are aware of recent false publications regarding a hostile group’s attempt to carry out a cyber-attack on Bazan. Please note that the information and images being circulated are entirely fabricated and have no association with Bazan or its assets. While our image website briefly experienced disruption during a DDoS attack, no damage was observed to the company’s servers or assets. This appears to be an act of propaganda aimed at spreading misinformation and causing a consciousness effect.”

“Our cybersecurity measures are vigilant, we are working closely with the Israeli National Cyber Directorate and our partners to monitor any suspicious activity to ensure the safety and integrity of our operations.”

The hacktivist group further implied that it had breached the petrochemicals giant via an exploit targeting a Check Point firewall at the company.

Alleged Check Point Firewall exploit used by threat actors
Alleged Check Point Firewall exploit used by threat actors

The IP address (194.xxx.xxx.xxx) purportedly belonging to the firewall device is indeed assigned to Oil Refineries Ltd., BleepingComputer could confirm via public records. At the time of writing, the IP address is returning a “Forbidden,” error message when accessed in our test.

A Check Point spokesperson stressed that “none of these claims are true” and reiterated the refinery’s findings in an email to BleepingComputer.

“There isn’t any past vulnerability which enabled such an attack,” the Check Point representative further clarified.

Lastly, CyberAvengers boasts that they are responsible for the 2021 fires at the Haifa Bay petrochemical plants caused by a pipeline malfunction. In 2020, the same group of threat actors also claimed attacks on 28 Israeli railway stations by targeting more than 150 industrial servers.

BleepingComputer has not been able to independently verify the veracity of these prior claims made by the threat actor.

Update, July 30th 12:52 PM ET: Edited the article to include statements from Bazan Group and Check Point received after publishing.

 

(c) Lawrence Abrams

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:42 pm, Jun 30, 2025
weather icon 26°C
L: 24° | H: 27°
clear sky
Humidity: 60 %
Pressure: 1014 mb
Wind: 6 mph SE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
24° | 27°°C 0 mm 0% 11 mph 63 % 1015 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
19° | 26°°C 0 mm 0% 12 mph 75 % 1024 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 7 mph 53 % 1029 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 10 mph 47 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
16° | 21°°C 1 mm 100% 12 mph 90 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
23° | 25°°C 0 mm 0% 3 mph 59 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 22°°C 0 mm 0% 3 mph 63 % 1014 mb 0 mm/h
Tomorrow 7:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 61 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
28° | 28°°C 0 mm 0% 3 mph 44 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 6 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
34° | 34°°C 0 mm 0% 8 mph 26 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
32° | 32°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
25° | 25°°C 0 mm 0% 8 mph 46 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,726.36
0.08%
Ethereum(ETH)
€2,141.69
2.99%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.95
4.59%
Solana(SOL)
€134.28
4.10%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.142338
1.58%
Shiba Inu(SHIB)
€0.000010
0.00%
Pepe(PEPE)
€0.000009
2.69%
Scroll to Top