The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Airlines/Aviation
Breach intelligence, attack campaigns, and threat reports targeting the Airlines/Aviation sector.
Explore Other Sectors
Airlines/Aviation Threat Reports
Caesars Entertainment 2023 Loyalty Program Data Breach: A Wake-Up Call for Cybersecurity
In September 2023, Caesars Entertainment disclosed a cyberattack that compromised the personal data of its loyalty program members, including Social Security and driver's license numbers. The breach, attributed to the cybercriminal group 'Scattered Spider' operating under the ALPHV/BlackCat syndicate, did not disrupt casino or online operations. Reports suggest Caesars may have paid a partial ransom of $15 million, though the total demand was $30 million. This incident underscores the growing threat of loyalty program fraud, where attackers exploit personal data for financial gain. The rise in such breaches highlights the need for enhanced security measures and consumer vigilance to protect sensitive information.
6 months ago
Kill Chain
Chinese Cyber Threat Targets Asian Critical Infrastructure
Since at least 2020, a Chinese-speaking threat actor identified as CL-UNK-1068 has been conducting cyber-espionage campaigns targeting critical infrastructure sectors across South, Southeast, and East Asia. The sectors affected include aviation, energy, government, law enforcement, pharmaceuticals, technology, and telecommunications. The attackers exploit vulnerabilities in public-facing web servers to gain initial access, deploying web shells like GodZilla and AntSword to maintain control. They employ tools such as Mimikatz and LsaRecorder for credential theft, and utilize custom malware alongside open-source utilities to facilitate lateral movement and data exfiltration. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))This incident underscores the persistent and evolving nature of cyber threats from state-sponsored actors, particularly those linked to China. The use of sophisticated tools and techniques highlights the need for organizations to enhance their cybersecurity measures to detect and mitigate such threats effectively. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))
6 months ago
Kill Chain
Iranian APT MuddyWater Infiltrates U.S. Networks Using Dindoor Backdoor
In early February 2026, the Iranian state-sponsored hacking group MuddyWater (also known as Seedworm) infiltrated networks of multiple U.S. organizations, including a bank, an airport, and a software company with Israeli operations. The attackers deployed a previously unknown backdoor named Dindoor, which utilizes the Deno JavaScript runtime for execution. Additionally, they attempted data exfiltration using the Rclone utility to a Wasabi cloud storage bucket. The initial access methods remain unclear, but MuddyWater is known for using phishing emails and exploiting vulnerabilities in public-facing applications. ([thehackernews.com](https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html?utm_source=openai)) This incident underscores the evolving capabilities of Iranian threat actors, who have demonstrated improved tooling and social engineering tactics. The timing of these intrusions, coinciding with escalating geopolitical tensions following U.S. and Israeli military actions, highlights the potential for cyber operations to serve as instruments of state power during periods of conflict. ([thehackernews.com](https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerability in Labkotec LID-3300IP Threatens Industrial Control Systems
In March 2026, a critical vulnerability (CVE-2026-1775) was identified in Labkotec's LID-3300IP ice detector software, allowing unauthenticated attackers to alter device parameters and execute operational commands via specially crafted packets. This flaw, stemming from missing authentication for critical functions, poses significant risks to industrial control systems, particularly in sectors like energy and communications. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1775?utm_source=openai)) The vulnerability underscores the growing threat landscape for industrial control systems, emphasizing the need for robust authentication mechanisms and network security practices to prevent unauthorized access and potential operational disruptions.
6 months ago
Kill Chain
MuddyWater's Operation Olalampo: A New Era of Cyber Threats in MENA
In early 2026, the Iranian state-sponsored APT group MuddyWater launched 'Operation Olalampo,' targeting organizations across the Middle East and North Africa (MENA) region. The campaign utilized sophisticated spear-phishing emails with malicious Microsoft Office documents to deploy new malware families, including GhostFetch, HTTP_VIP, CHAR, and GhostBackDoor. These tools enabled the attackers to perform system reconnaissance, execute remote commands, and exfiltrate sensitive data, compromising entities in sectors such as telecommunications, government, and energy. This incident underscores a significant evolution in MuddyWater's tactics, notably their adoption of Rust-based malware and AI-assisted development processes. The group's enhanced capabilities and persistent targeting of critical infrastructure highlight the escalating cyber threat landscape in the MENA region, emphasizing the need for robust cybersecurity measures and vigilance against advanced persistent threats.
7 months ago
Kill Chain
Sophisticated Phishing Attacks Target Japanese Companies in 2026
In February 2026, a series of sophisticated phishing campaigns targeted Japanese-speaking individuals by impersonating reputable companies such as ANA, DHL, and myTOKYOGAS. These emails, originating from domains with a .cn top-level domain, utilized the Foxmail email client and directed recipients to counterfeit login pages designed to harvest sensitive credentials. The consistent use of the Foxmail client and .cn domains suggests coordination by a single threat actor. This incident underscores the evolving tactics of cybercriminals in crafting culturally and linguistically tailored phishing schemes to deceive users and compromise personal information. The prevalence of such targeted attacks highlights the necessity for enhanced vigilance and robust email filtering mechanisms to protect against credential theft and potential financial loss.
7 months ago
Kill Chain
2025 University of Hawaii Cancer Center Ransomware Breach: Research Data Compromised
In August 2025, the University of Hawaii Cancer Center experienced a ransomware incident that resulted in threat actors encrypting systems associated with a specific research project. The intrusion led to the exfiltration and encryption of files, some of which dated back to the 1990s and included research participant data containing Social Security numbers, predating modern de-identification practices. While only research files and not clinical or patient treatment data were affected, the disruption necessitated a comprehensive remediation effort including system replacements, forensic investigations, ransomware payment for decryption, and negotiations for deletion of exfiltrated information. This incident underscores the targeting of higher-education and research organizations by ransomware attackers seeking both data and financial gain. With universities increasingly storing decades-old PII, and ransomware groups escalating both exfiltration and extortion, the breach exemplifies the urgency of robust detection, legacy data management, and compliance disciplines in the education and research sector.
8 months ago
Kill Chain
Australia 2024 Airport Evil Twin WiFi Attack: Network Intrusion Threat Exposed
In 2024, Australian authorities sentenced a 44-year-old man to over seven years in prison for orchestrating a series of 'evil twin' WiFi attacks at major Australian airports. The perpetrator set up rogue wireless networks mimicking legitimate airport WiFi, luring unsuspecting travelers into connecting and unknowingly handing over sensitive data, including credentials and personal information. Over a prolonged period, these attacks evaded detection due to the sophistication of the deceptive access points and inherent insecurity of public wireless networks. The incident highlighted significant risks for both individuals and organizations, demonstrating effective tactics for harvesting credentials in the wild. This case exemplifies a broader trend of attackers exploiting public and unsecured networks to launch network intrusion campaigns, especially as remote work and mobile connectivity surge. Such methods bypass conventional perimeter defenses and increase compliance and regulatory pressures for organizations to protect data in transit.
8 months ago
Kill Chain
Executive Breach Brief: Scattered LAPSUS$ Hunters’ 2025 Salesforce Ransomware Campaign
In May 2025, the Scattered LAPSUS$ Hunters (SLSH) cybercriminal group orchestrated a wide-scale ransomware and data extortion campaign targeting the Salesforce environments of over thirty major corporations, including brands like Toyota, FedEx, Disney/Hulu, and UPS. Leveraging sophisticated voice phishing for initial access, SLSH tricked employees into connecting malicious apps to internal Salesforce portals, facilitating rapid exfiltration of sensitive corporate data. Public threats of mass data leaks via their extortion site, insider recruitment, and the deployment of the new ShinySp1d3r ransomware further amplified organizational and reputational risk, prompting companies and regulators to respond swiftly. This incident exemplifies the convergence of advanced social engineering and ransomware-as-a-service models, alongside a growing ecosystem of cybercrime collaboration. Attackers’ use of collaboration platforms, custom malware, and drive to monetize breaches through both data theft and extortion spotlights the need for zero trust and enhanced compliance controls in identity, SaaS, and egress security.
8 months ago
Kill Chain
Iberia Data Breach (2024): Supply Chain Compromise Exposes Airline Customer Data
In June 2024, Spanish airline Iberia disclosed a significant data breach originating from the compromise of an external supplier. Attackers leveraged a third-party network to steal approximately 77 GB of sensitive customer data, including contact information, travel details, and partial payment card data. The breach was first publicized on underground forums, with threat actors claiming possession of the data days before Iberia notified its customers. The incident underscores how supply chain vulnerabilities can directly jeopardize core business operations and customer trust, disrupting service continuity and triggering regulatory scrutiny for the airline industry. This breach illustrates the ongoing escalation of supply chain attacks, where organizations are exposed through weak vendor controls. With similar tactics increasingly exploited against critical infrastructure, maintaining robust controls over partners is now essential in light of growing attacker sophistication and tightening data protection requirements.
8 months ago
Kill Chain
Clop Ransomware Hits Washington Post via Oracle Zero-Day in 2024
In July and August 2024, The Washington Post fell victim to a cyberattack orchestrated by the Clop ransomware group, which exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. Attackers accessed the company’s Oracle environment for over six weeks, ultimately stealing sensitive HR data on nearly 10,000 current and former employees and contractors, including names, bank account details, and Social Security numbers. The breach went undetected until late September when Clop contacted executives with extortion demands. The company confirmed the scope of stolen data in late October, after initiating an internal investigation. This incident underscores the growing trend of threat actors leveraging zero-day vulnerabilities in widely used enterprise software to facilitate mass data theft and extortion. With ransomware groups like Clop escalating the use of targeted campaigns against technology supply chains, organizations face heightened exposure to financial, regulatory, and reputational risk.
8 months ago
Kill Chain
GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers
GlobalLogic, a subsidiary of Hitachi, suffered a significant data breach after the Clop ransomware group exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. The breach, which began on July 10, 2024, went undetected for months and resulted in the theft of sensitive human resources data for nearly 10,500 current and former employees. Attackers accessed items such as names, SSNs, salary and bank details, passport information, and more, ultimately issuing extortion demands and threatening to leak the stolen data. GlobalLogic promptly initiated incident response actions, notified regulators, and applied Oracle's critical software patches to mitigate the threat after discovering the breach on October 9, 2024. This incident is part of a broader campaign targeting multiple Oracle customers, with ransom demands reaching as high as $50 million and almost 30 organizations named as victims on Clop’s data leak site. This attack underscores the ongoing threat of ransomware groups exploiting enterprise application vulnerabilities and highlights the growing risks posed by sophisticated supply chain and zero-day attacks. Organizations relying on popular ERP software must increase vigilance and prioritize patch management, while regulators and security leaders raise concern over attackers' speed, stealth, and extortion tactics.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports