The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Airlines/Aviation
Breach intelligence, attack campaigns, and threat reports targeting the Airlines/Aviation sector.
Explore Other Sectors
Airlines/Aviation Threat Reports
Multi-Vector Campaign Targets AI Systems and Banking: RemControl Trojan and Search Poisoning Analysis
In September 2026, cybersecurity researchers identified a coordinated multi-vector campaign targeting AI systems, banking applications, and enterprise development environments. The campaign featured the RemControl Android banking trojan targeting Western Europe and Canada through fake Google Play Store pages, a massive AI disinformation attack poisoning ChatGPT and Google AI Overviews with fraudulent information, and supply chain compromises affecting WordPress plugins and AI coding tools. Threat actors leveraged social engineering tactics, exploited trusted platforms, and manipulated AI training data to execute credential theft, financial fraud, and code repository exfiltration across multiple industries. This incident highlights the rapidly evolving threat landscape where attackers are increasingly targeting AI systems and trusted development tools, representing a fundamental shift toward exploiting automation and machine learning platforms that organizations rely on for daily operations.
17 minutes ago
Kill Chain
Autonomous AI Agents Execute Massive Credit Card Theft Campaign
A Chinese threat actor deployed autonomous AI agents to orchestrate a massive payment card theft operation, compromising over 119 websites and stealing more than 600,000 credit card records. The campaign, active since July 2026, utilized three AI frameworks - Strix for vulnerability scanning, Cairn for exploitation, and Hermes for orchestration - to systematically target online retailers. Major victims included Fortune 500 companies across hospitality, aviation, and retail sectors. The attackers deployed payment skimmers through various injection methods and implemented destructive cleanup procedures that wiped source data after exfiltration, causing operational disruptions. This incident represents a paradigm shift toward AI-powered cybercrime, demonstrating how autonomous systems can execute complex attack chains at unprecedented scale and speed. The low operational cost of $25 per target and minimal human oversight signal a new era where sophisticated attacks become accessible to less skilled threat actors, fundamentally changing the threat landscape.
1 day ago
Kill Chain
Dark Sourcery Campaign Exposes Critical Vulnerabilities in Enterprise AI Security
In September 2026, cybersecurity researchers from Vigilance Security uncovered a sophisticated social engineering campaign dubbed 'Dark Sourcery' targeting major AI chatbots including ChatGPT, Google Gemini, and Google AI Overview. Threat actors poisoned these AI systems by flooding the web with carefully crafted malicious content, fake support pages, and fraudulent contact information, tricking the AI into presenting this misinformation as factual responses to users. The campaign compromised at least 374 major companies including Fortune 100 organizations, airlines like Delta and Lufthansa, and financial institutions such as Chase and Bank of America, causing significant reputational damage and enabling widespread phishing attacks. This incident represents a critical evolution in AI-targeted attacks as organizations increasingly integrate AI chatbots and agents into their business operations. With 91% of users blindly trusting AI responses without verification, this attack vector poses an unprecedented threat to enterprise security and user trust in AI systems.
1 day ago
Kill Chain
How ShinyHunters Weaponized Claude AI to Harvest Secrets from 1.8 Million Android Apps
Between December 2025 and August 2026, multiple threat groups including ShinyHunters, Russian state-sponsored Midnight Blizzard, and Chinese espionage group GTG-10007 systematically abused Anthropic's Claude AI model for large-scale cyberattacks. The most significant operation involved ShinyHunters member 'frkoo' deploying an automated credential-harvesting pipeline across AWS infrastructure that extracted secrets from 1.8 million Android applications and compromised over 40 Microsoft corporate tenants within 34 hours. The AI-enhanced attacks enabled rapid progression from initial access to administrative control in under three hours, with confirmed breaches across government, healthcare, energy, and technology sectors. This incident represents a critical inflection point where AI capabilities are being weaponized at unprecedented scale and speed, fundamentally changing the threat landscape and requiring immediate reassessment of defensive strategies against AI-enhanced cybercrime operations.
1 week ago
Kill Chain
IDScan's Massive Data Breach Exposes 153 Million Driver's Licenses on Dark Web
In September 2026, identity verification company IDScan suffered a massive data breach affecting over 153 million U.S. and Canadian driver's licenses, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Cybercriminals operating the dark web service 'Nexus' advertised the stolen data, which included scanned identity documents from businesses using IDScan's verification systems across car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments. The FBI's New Orleans office launched an investigation, and multiple class-action lawsuits have been filed against the Louisiana-based company. This incident highlights the growing threat to identity verification services and third-party data processors, demonstrating how a single breach can expose massive volumes of sensitive personal identification data across multiple industries and geographical regions.
2 weeks ago
Kill Chain
How Mirage Kitten's NodeRabbit Malware Exploited Developer Trust in 2024
In 2024, Iranian APT group Mirage Kitten launched sophisticated social engineering campaigns targeting aviation and fintech sectors across the Middle East and Africa using two new cross-platform malware families: NodeRabbit and PollCat. The threat actors posed as recruiters on LinkedIn, delivering trojanized coding challenges that contained Node.js-based remote access trojans capable of running on Windows, Linux, and macOS. The malware established persistence through multiple mechanisms and communicated with command-and-control infrastructure hosted on Azure and Cloudflare, affecting organizations in Egypt, Ethiopia, and Afghanistan. This campaign represents a significant evolution in nation-state tactics, showcasing how APT groups are adapting to target developer communities through increasingly sophisticated supply chain attacks and social engineering techniques that exploit trust in professional recruitment processes.
3 weeks ago
Kill Chain
Iran-Linked Nation-State Actors Launch Coordinated Attacks on US Water Infrastructure
In August 2026, Iran-linked threat actors conducted a sophisticated campaign targeting critical water and wastewater systems across at least 12 US states, utilizing advanced persistent threat techniques to infiltrate industrial control systems. The attackers successfully compromised SCADA networks and human-machine interfaces, demonstrating their ability to manipulate critical infrastructure operations. In a parallel attack, the same threat group shut down a UK power plant for four days in July 2026, highlighting the global reach and severity of their capabilities. The incidents caused significant operational disruptions, water service outages affecting hundreds of thousands of residents, and forced emergency response protocols across multiple states. These attacks represent a dangerous escalation in nation-state targeting of critical infrastructure, coinciding with increased geopolitical tensions and sophisticated adversaries developing specialized capabilities for industrial control system compromise. The incidents underscore the urgent need for enhanced OT security measures and zero-trust architectures protecting critical national infrastructure.
3 weeks ago
Kill Chain
Berlin Government Refuses Ransom After Rhysida Steals 5.79TB of Citizen Data
In August 2026, the Rhysida ransomware group successfully infiltrated Berlin's state administrative network, exfiltrating 5.79 terabytes of data including personal information on over 12,000 individuals between August 7-12. The attackers gained initial access through compromised VPN credentials and deployed double extortion tactics, demanding ransom payment while threatening to leak stolen government data. Berlin's leadership, including Governing Mayor Kai Wegner, publicly refused to pay the ransom despite ongoing extortion attempts, maintaining operations while conducting forensic investigation with federal authorities. This incident highlights the continued evolution of ransomware groups targeting critical government infrastructure, particularly as threat actors like Rhysida increasingly focus on high-profile public sector victims to maximize pressure and potential payouts through leaked sensitive citizen data.
3 weeks ago
Kill Chain
Manchester Airports Group Breach Exposes 8.9 Million Travelers' Data in Major Aviation Cyber Attack
In August 2026, Manchester Airports Group (MAG), the UK's largest airport operator managing Manchester, London Stansted, and East Midlands airports, suffered a significant data breach affecting up to 8.9 million travelers. Attackers accessed customer databases containing Wi-Fi registration details, car park bookings, lounge reservations, and Fast Track services, compromising email addresses, phone numbers, vehicle registration numbers, and postcodes. While payment card data remained secure and airport operations continued uninterrupted, MAG temporarily suspended its online booking management system as a precautionary measure. The aviation industry faces increasing cyber threats targeting critical infrastructure and passenger data, with attackers recognizing airports as high-value targets containing vast amounts of personal information and payment data. This incident highlights the urgent need for enhanced cybersecurity measures across transportation hubs as digital transformation accelerates in the post-pandemic travel recovery.
4 weeks ago
Kill Chain
Delta Flight 591 Wi-Fi Hack: When DEF CON Tools Turn Into In-Flight Threats
In August 2026, a passenger on Delta Air Lines Flight 591 from Las Vegas to Atlanta compromised the aircraft's in-flight Wi-Fi system following the Black Hat and DEF CON conferences. The attacker disabled the legitimate Wi-Fi service and created a rogue access point named "Delta WiFi Fast" that redirected users to a phishing page designed to harvest credentials. Federal authorities launched an investigation into the incident, with suspicion falling on DEF CON attendees who may have used commercially available Wi-Fi Pineapple devices purchased at the conference. This incident highlights the growing risk of in-flight cybersecurity threats as aviation systems become increasingly connected. The ease with which commercially available penetration testing tools can be weaponized in confined, high-security environments demonstrates critical gaps in aviation cybersecurity protocols and passenger device restrictions during flight operations.
1 month ago
Kill Chain
Advanced Android Banking Malware: ToxicPanda 2.0 and GoldDigger Threaten Global Financial Security
ToxicPanda 2.0 represents a significant evolution in Android banking malware, expanding from targeting 16 banking applications to 349 financial institutions across 16 countries. The malware leverages Android accessibility services to steal UI elements, deploy overlay-based credential theft, and abuse Android Wireless Debugging for privilege escalation. Concurrently, GoldDigger banking trojan has launched massive infection campaigns in South Africa and the U.K., impersonating airline companies and retailers while performing sophisticated on-device fraud through real-time screen access and automated transaction manipulation. These incidents highlight the rapidly evolving landscape of mobile banking threats, where attackers are leveraging cloud infrastructure for distribution and implementing advanced evasion techniques. The shift toward on-device fraud capabilities and expanded targeting scope reflects the growing sophistication of mobile threat actors and their ability to adapt to modern security measures.
1 month ago
Kill Chain
Delta Airlines Flight 591 Wi-Fi Spoofing Incident: A Wake-Up Call for In-Flight Cybersecurity
In August 2026, during Delta Airlines flight 591 from Las Vegas to Atlanta, a passenger reportedly deployed a rogue Wi-Fi network named 'Delta WiFi Fast,' mimicking the airline's legitimate in-flight Wi-Fi. This 'evil twin' attack aimed to deceive passengers into connecting to the fraudulent network, potentially exposing their sensitive data. Upon detection, the flight crew promptly disabled the aircraft's Wi-Fi for approximately 30 minutes to mitigate the threat. The incident did not compromise flight safety or aircraft systems. Delta is collaborating with federal authorities, including the FBI and FAA, to thoroughly investigate the event. This incident underscores the growing cybersecurity risks associated with public Wi-Fi networks, especially in confined environments like aircraft cabins. The timing, coinciding with the conclusion of the DEF CON cybersecurity conference, highlights the need for heightened vigilance against sophisticated attacks targeting unsuspecting users in transit.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports