✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Airlines/Aviation
Breach intelligence, attack campaigns, and threat reports targeting the Airlines/Aviation sector.
Explore Other Sectors
Airlines/Aviation Threat Reports
Clop Breaches Envoy Air via Oracle EBS Zero-Day in 2025: Key Lessons in Ransomware Defense
In October 2025, Envoy Air, a regional subsidiary of American Airlines, confirmed that attackers compromised business information from its Oracle E-Business Suite (EBS) application. The Clop ransomware/extortion group exploited a newly discovered Oracle EBS zero-day (CVE-2025-61882) to access internal systems in August 2025. Upon discovery, Envoy initiated an investigation, notifying law enforcement and confirming that no sensitive customer or employee data was affected, though limited business and commercial contact details were exposed. This incident underscores the rising trend of ransomware and extortion groups leveraging zero-day vulnerabilities in key enterprise platforms. The Clop gang continues to target multiple industries through advanced attacks on widely used software, emphasizing the urgent need for robust patch management, east-west traffic security, and zero trust segmentation strategies.
6 months ago
Kill Chain
Satellite Communications Exposed: 2025’s Unencrypted Data Crisis
In mid-2025, a landmark study revealed that a vast portion of global geostationary satellite communications—including critical infrastructure, government, corporate, and consumer data—are transmitted unencrypted. Security researchers, using inexpensive commercially available satellite equipment, intercepted highly sensitive transmissions such as internal communications, private calls and SMS, and in-flight internet traffic. Because thousands of geostationary transponders broadcast across enormous geographic areas, these unprotected signals can be passively accessed by unauthorized parties from virtually anywhere within satellite coverage zones, putting confidential data at significant risk of interception and exploitation. This incident underscores a persistent and growing concern regarding the lack of robust encryption in satellite communications, even as regulations and cyber threats evolve rapidly. Increasing satellite connectivity for aviation, maritime, and remote access drives urgency around encryption, as adversaries and data brokers exploit these vulnerabilities on a global scale.
6 months ago
Kill Chain
Startling Satellite Breach: How $600 Unlocked a Global Data Leak in 2025
In early 2025, researchers from the University of Maryland and UC San Diego revealed widespread leakage of sensitive and private data—including military and telecom communications—through unencrypted transmissions sent over geostationary (GEO) satellites. By using only $600 in commercially available equipment, the team passively intercepted vast amounts of plaintext data from major organizations, government entities, and telecom users around the globe. The incident highlighted fundamental lapses in network-layer encryption practices, allowing phone calls, SMS messages, internal application data, and even military vessel information to leak with no authentication or protection. The research further demonstrated that even technically unsophisticated actors could compromise critical satellite backhaul links using minimal resources. This event underscores the urgent need for end-to-end encryption and robust monitoring of satellite communications as reliance on these channels increases and barriers to interception continue to fall. Government and industry must now address the rapidly evolving risk landscape, especially as critical infrastructure becomes more dependent on satellite connectivity.
6 months ago
Kill Chain
Qantas 2025 Data Breach: Scattered LAPSUS$ Defies Legal Barriers
In October 2025, Australian airline Qantas suffered a major data breach when threat actor group Scattered LAPSUS$ released sensitive customer and employee data following an extortion attempt. Despite Qantas obtaining a legal injunction aimed at stopping the dissemination of the information, the attackers proceeded to publish the stolen data, rendering legal intervention ineffective. The incident exposed personal records and travel information, spotlighting ongoing organizational vulnerabilities to data extortion and public leaks driven by sophisticated attackers exploiting access. The breach prompted widespread media coverage and concern over enforcement power in digital incidents. This attack underscores the growing trend of double extortion tactics, where attackers threaten to release stolen data for leverage, outpacing regulatory or legal controls. The event exemplifies the surge in ransomware and extortion methods targeting aviation and critical infrastructure, reinforcing the urgent need for proactive, technical mitigations and incident preparedness planning.
6 months ago
Kill Chain
Inside the Qantas 2025 Ransomware Breach: Why Legal Measures Can’t Stop Data Leaks
In October 2025, Qantas, the Australian airline, suffered a ransomware attack attributed to the 'Scattered LAPSUS$ Hunters' group. Attackers claimed to have breached Qantas’ systems via a supply chain vulnerability, exfiltrating personal and loyalty program data of potentially hundreds of thousands of customers, including high-profile individuals. After initial extortion attempts, the stolen data—including names, emails, and frequent flyer records—was publicly leaked when Qantas refused to pay ransom. Qantas took legal steps, securing a court injunction to limit data dissemination, but these measures proved ineffective at curbing the spread among criminal and international actors. This breach highlights the ongoing threat of ransomware and data extortion campaigns targeting major brands, frequently leveraging supply-chain infiltration and cloud-based service weaknesses. The incident also underscores the limited real-world efficacy of legal remedies like injunctions, as well as evolving attacker strategies involving public shaming and mass data exposure.
6 months ago
Kill Chain
Salesforce Breach 2024: Scattered Lapsus$ Hunters' Massive Data Extortion Campaign
In October 2024, the cybercriminal collective Scattered Lapsus$ Hunters resurfaced with a dedicated leak site, threatening to publish stolen data related to Salesforce customers if their extortion demands were not met. This group, an alliance of threat actors including Scattered Spider, Lapsus$, and ShinyHunters, allegedly compromised Salesforce environments through social engineering—specifically vishing IT support personnel to obtain credentials and, in parallel campaigns, exploiting OAuth token theft. The attackers claimed to possess approximately one billion records from 39 prominent organizations, including sensitive personally identifiable information (PII) like Social Security and driver’s license numbers. This incident underscores the increased targeting of SaaS platforms via identity and access manipulation, as well as the growing sophistication of multinational threat actor collaborations. It signals elevated risk for organizations relying on cloud applications and highlights the necessity of enforcing multi-factor authentication and vigilant third-party access controls.
6 months ago
Kill Chain
WestJet 2025 Data Breach: How Social Engineering and Remote Access Led to Massive Data Exposure
In June 2025, Canadian airline WestJet suffered a major data breach affecting approximately 1.2 million customers. Threat actors exploited social engineering to reset an employee’s password, gaining access through Citrix systems and compromising both Windows and Microsoft cloud networks. The attackers were able to exfiltrate sensitive personal data, including full names, dates of birth, physical addresses, passport or government IDs, travel information, rewards member data, and select customer service interactions. While no credit card numbers or passwords were disclosed, the incident required investigation by law enforcement and forced WestJet to notify affected users and authorities across North America, offering free identity monitoring. This breach highlights the growing effectiveness of identity-based attacks, particularly those leveraging social engineering to bypass traditional security controls via remote access platforms. With aviation and travel industries increasingly targeted, this incident underscores the urgent need for modern Zero Trust approaches and continuous monitoring of east-west traffic within enterprise networks.
6 months ago
Kill Chain
WestJet Data Breach 2025: Passport Info Exposed in Major Airline Cyberattack
In June 2025, Canadian airline WestJet revealed a cybersecurity breach that resulted in the exposure of sensitive customer information, including names, dates of birth, mailing addresses, travel documents such as passports and government IDs, requested accommodations, complaints, and loyalty program data. The breach, disclosed after disruptions to internal systems and the company’s mobile app, was investigated over several months, with findings confirmed in mid-September. While no official attribution has been confirmed, the notorious Scattered Spider threat group was active in targeting the aviation industry at the time. The FBI is assisting with the investigation, and all affected customers have been notified. This breach is of significant concern as it exemplifies the intensifying targeting of travel and aviation sectors by sophisticated threat actors using advanced social engineering and credential-harvesting techniques. The incident also underscores increasing regulatory scrutiny and customer awareness around identity-related attacks and privacy risks in critical infrastructure industries.
6 months ago
Kill Chain
RTX Ransomware Attack Disrupts Major European Airports in 2025
In September 2025, RTX Corporation (formerly Raytheon Technologies) experienced a significant ransomware attack targeting its Collins Aerospace Multi-User System Environment (MUSE) passenger processing platform. The ransomware—suspected to be from the Hardbit or Loki ransomware families—caused widespread operational disruptions, leading to flight cancellations and delays at major European airports including London Heathrow, Brussels, Cork, Dublin, and Berlin. The attack was detected on September 19th, prompting RTX to initiate a full incident response, notify authorities, and deploy technical mitigations across affected customer networks. Law enforcement arrested a UK-based suspect linked to the attack, underscoring the event’s criminal intent and sophistication. This incident highlights a rising trend of ransomware groups targeting critical infrastructure and supply chain applications, often by leveraging commodity Ransomware-as-a-Service (RaaS) tools. It also signals a shift in attacker behavior towards less sophisticated malware, which can still yield significant operational disruption due to integrated, shared technology platforms in aviation and other sectors.
6 months ago
Kill Chain
Teen Arrested in 2023 Las Vegas Casino Ransomware Attacks Linked to Scattered Spider
In late 2023, Las Vegas casinos suffered major cyberattacks attributed to the Scattered Spider threat group, resulting in widespread operational disruption. The attacks targeted MGM Resorts International and Caesars Entertainment, leveraging sophisticated social engineering and phishing tactics to gain network access, move laterally, and ultimately extort ransom payments. MGM reported losses exceeding $100 million, while Caesars reportedly paid $15 million to mitigate risks. In June 2024, a local teenage suspect was arrested in connection to these events, highlighting the involvement of young, native English-speaking cybercriminals and a broader international law enforcement response. This incident exemplifies the increasing prevalence of highly organized, technology-savvy ransomware and extortion campaigns that rely on social engineering and identity-centric attack vectors. Organizations across industries face rising risks as threat groups adopt coordinated, multifaceted tactics to exploit internal and hybrid cloud environments.
6 months ago
Kill Chain
Ransomware Attack Disrupts Major European Airports via Collins Aerospace in 2025
In September 2025, a major ransomware attack on Collins Aerospace, a critical provider of check-in and boarding systems, triggered widespread disruptions at several major European airports, including Heathrow, Brussels, and Berlin Brandenburg. The hackers targeted the Multi-User System Environment (MUSE) platform, which airlines rely on to coordinate check-in desks and gate assignments. As a result, more than 100 flights were delayed or cancelled, and thousands of passengers faced manual check-in procedures while airports scrambled to contain the operational fallout. Law enforcement and cybersecurity agencies are actively investigating, prioritizing the restoration of affected systems and mitigation of further impact. This incident underlines the escalating risk posed by ransomware targeting supply chain infrastructure and the aviation sector’s reliance on shared IT systems. It also reflects a broader trend of cybercriminals exploiting third-party service dependencies, bringing renewed urgency to layered defense strategies and zero-trust adoption for business-critical environments.
6 months ago
Kill Chain
Airport Check-In Disruption: 2024 Supply-Chain Breach at Heathrow
In June 2024, a major disruption struck multiple European airports, including London Heathrow, after a cyberattack targeted a third-party provider responsible for check-in kiosk software. The supply-chain attack led to widespread check-in outages, flight delays, and cancellations, impacting thousands of travelers over the weekend. Initial investigation suggests that attackers compromised the software vendor’s infrastructure—potentially with ransomware or through lateral movement via third-party access—causing operational downtime for airlines and airport operators relying on their services. The incident highlights growing dependency risks stemming from the use of specialized external IT vendors in critical national infrastructure, especially in aviation. This event underscores the accelerating trend of supply-chain attacks, where threat actors exploit weaker links outside direct company control. With aviation systems under heightened scrutiny and ransomware groups often targeting critical operations, organizations across sectors must reevaluate third-party security, segmentation, and visibility to mitigate cascading impacts from vendor compromises.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports