Chemco
Qilin ransomware targets 60-year-old Calgary manufacturer serving energy, oil & gas, and utilities sectors.
What happened?
Qilin ransomware group attacked Chemco, a Calgary-based manufacturing company founded in 1962. Chemco specializes in pump and compressor engineering for energy, logistics, oil & gas, and utilities industries.
Qilin—also known as Agenda—is a ransomware-as-a-service operation active since 2022. They've targeted healthcare, education, and industrial organizations globally, combining encryption with data theft for double extortion.
What data was actually inside?
Mid-market manufacturers hold engineering specifications, customer relationships, and operational data that larger companies depend on. Chemco's data likely includes pump and compressor designs, customer service records, and supplier relationships across six decades of operation.
Energy sector equipment specifications are valuable. The technical data enabling pumps and compressors to operate in oil fields, utilities, and logistics operations represents proprietary engineering accumulated over 60 years.
Who gets hurt and how?
Chemco's employees. Their customers in energy and utilities who depend on equipment and service. Suppliers in their procurement chain. A 60-year-old company has relationships built across generations of business partnerships.
Critical infrastructure supply chain attacks ripple outward. When a component manufacturer is compromised, every customer depending on that equipment faces questions about their own operational security.
What did they think they were doing right?
Mid-market manufacturers operate with resources proportional to their size. A company founded in 1962 has core business expertise in pumps and compressors, not cybersecurity. They serve critical infrastructure without critical infrastructure security budgets.
That resource mismatch makes them attractive targets. Ransomware groups know smaller manufacturers can't afford extended downtime. The pressure to restore operations and maintain customer relationships creates urgency that attackers exploit.
What did they not know about their own data?
Sixty years of engineering documentation, customer records, and operational data. Legacy systems from different technology eras. Information that predates modern data management practices. Understanding what exists across six decades requires deliberate inventory.
Manufacturing companies often run OT systems alongside IT networks. Equipment control systems designed for reliability rather than security. The convergence creates attack paths that traditional IT security may not cover.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
Canadian privacy regulators and potentially Alberta's energy sector oversight. Customer notifications across their service base. Assessment of whether operational systems—not just corporate IT—were affected.
For a 60-year-old manufacturer, rebuilding isn't just about data recovery. It's about maintaining customer relationships and operational capability that took decades to build. The reputation cost compounds the technical cost.
What would have changed the outcome?
Data inventory that spans both IT and OT environments—understanding what sensitive information exists across decades of accumulated systems.
Mid-market manufacturers can't match enterprise security budgets. But they can know what they have. Understanding data inventory enables prioritization: protecting the most sensitive assets first, implementing retention policies that limit exposure, and assessing breach scope when incidents occur.
Chemco found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.