Desk live·
ForensicPost
Ransomware/Availability/File 23-0625

Suncor Cyberattack Left 1,500 Petro-Canada Sites Unable to Take Card Payments

Suncor was breached around 21 June 2023 and disclosed on the 25th. More than 1,500 Petro-Canada sites lost card payment, and the people who bore it were drivers with no relationship to the incident at all.

Constructed geometry · not a chart of case data
JurisdictionCanadaCalgarythe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSuncor Energy
ActorUnattributed
D. Kennedy11 min readConfidence: high3 sources reviewed

Suncor Energy was breached on or around 21 June 2023 and disclosed the incident on 25 June. More than 1,500 Petro-Canada retail sites were unable to accept card payments, with cash the only reliable means of payment; some supplier payments were also affected, and the loyalty programme was unavailable through the app and website.

Petro-Canada customer rewards data was later confirmed breached. Field operations were reported unaffected. The company replaced desktop and laptop computers during recovery, and executives reported most normal operations restored some months later.

The Cost Landed On People With No Connection To It

A driver at a Petro-Canada forecourt has no relationship with Suncor’s IT estate, was not a party to any decision, and had no way to prepare. They arrived, found cards refused, and either had cash or did not.

We have argued at 24-1231 and 22-0224 that availability harm goes uncounted. This file adds the distributional point: the harm was spread thinly across a very large number of uninvolved people, and thin wide harm is the kind no regime has ever been built to measure.

Cash-Only Is Not Neutral

Falling back to cash sounds like a mild inconvenience and it is not evenly distributed. It excludes people who do not carry cash, which increasingly means most people, and it lands hardest on anyone whose journey was not optional.

We have recorded degraded-mode fallbacks at 22-1002, where a hospital system moved to paper, and 22-1104, where a government did. Each fallback works for some people and fails for others, and the failure is never recorded because nobody collects the names of the customers who left.

Replacing The Laptops

The reported replacement of desktop and laptop computers during recovery is the detail that indicates how the response was scoped: a decision that cleaning endpoints was less trustworthy than replacing them.

We filed that judgement at 23-0518, where a vendor told customers to replace appliances rather than patch them, and 22-0224, where wiped modems had to be physically swapped. It is the most expensive form of confidence and organisations reach for it when they cannot prove what an intruder touched.

How we reported this

Compiled from contemporaneous reporting and the company’s statements, listed below. No ransomware operation is named — none was authoritatively identified. No figure for affected loyalty accounts is asserted and no cost figure is carried. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Suncor Energy cyberattack impacts Petro-Canada gas stationsBleepingComputer
  2. Suncor swaps out laptops after cybersecurity incident as energy sector takes stock of risksCBC News
  3. Suncor CEO says company mostly recovered from June cyberattackCybersecurity Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary