Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSwire Pacific Offshore (SPO) disclosed in late November 2021 that an unauthorized party had accessed some of its IT systems, resulting in the loss of confidential commercial information and personal data. The company said its global operations had not been materially affected. A contemporaneous report said the Clop operation claimed responsibility, but the number of people affected and the full contents of any exposed data were not confirmed by SPO.
What happened in the Swire Pacific Offshore breach?
Over the U.S. Thanksgiving weekend in November 2021, SPO disclosed that a third party had accessed some of its systems without authorization. In a statement reproduced by SecurityWeek on November 29, 2021, the company said the incident had caused the loss of “some confidential proprietary commercial information” and “some personal data.” It did not describe the intrusion method, identify a technical cause, or provide a recovery timeline.
SPO said it had reported the incident to authorities, started notifying affected parties, and was taking steps to improve security and mitigate the impact. The report did not give a completed notification count or details of the security measures.
What information was reportedly exposed?
SecurityWeek reported that the Clop operation published more than 56 archives of data it claimed to have stolen. The outlet said the archives appeared to include employee identity-card and passport scans, email addresses, bank-account numbers, phone numbers, internal login details, and commercial documents. This is a description of material allegedly leaked online, not a complete inventory confirmed by SPO.
#1 Best Overall
Did Clop attack SPO, and was ransomware involved?
SecurityWeek reported that Clop claimed responsibility for the attack. That establishes the group’s claim, not independent confirmation of attribution by SPO or authorities. The report characterized the incident as an apparent extortion attempt and said ransomware might have been used. SPO’s statement, as reproduced in the article, did not specify the attack type. The available reporting does not establish whether a ransom was demanded or paid.
How many people were affected?
The number of people whose data was affected was unclear in SecurityWeek’s November 29, 2021 account. Its estimate of roughly 2,500 employees described SPO’s workforce at the time; it was not a count of breach victims. The report did not state how many people received notifications.
Did the breach disrupt SPO’s operations?
SPO said the cyberattack had “not materially affected” its global operations. That was the company’s assessment at the time of disclosure; it should not be read as proof that there were no operational effects at all. SecurityWeek described the company as operating in 18 countries with a fleet of more than 50 offshore support vessels, figures that indicate the scale of the business but do not quantify incident impact.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What does the company’s security history establish?
SPO’s Sustainable Development Report for calendar year 2020 described cybersecurity as a material business issue. It said the company maintained a cybersecurity and information-classification policy, provided awareness education to shore and sea employees, periodically assessed its infrastructure, and conducted penetration testing in 2020; the report called that assessment “satisfactory.” Those pre-incident disclosures do not identify what control failed in 2021 or explain how the attackers gained access.
Rank #3
Swire Pacific Limited’s 2025 Sustainability Report lists group-level cybersecurity measures including a managed security operations centre, an incident-response retainer, attack-surface management, red-team attack simulation, and security-awareness programming. Because this is later, group-level information, it does not show that any of those capabilities handled SPO’s 2021 incident.
Quick Recap
What remains unknown?
- The exact number of affected individuals and the final scope of personal data exposure.
- The technical method of entry, any specific failed control, and a final investigation outcome.
- Whether a ransom was demanded or paid.
- The exact operational effects beyond the company’s statement that there was no material impact on global operations.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




