The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Airlines/Aviation
Breach intelligence, attack campaigns, and threat reports targeting the Airlines/Aviation sector.
Explore Other Sectors
Airlines/Aviation Threat Reports
Global Airports at Risk: Radiometrics VizAir 2025 Unauthenticated Access Exposes Critical Infrastructure
In November 2025, critical vulnerabilities were publicly disclosed in Radiometrics VizAir, a system widely deployed in global airport transportation infrastructure. The flaws (CVE-2025-61945, CVE-2025-54863, CVE-2025-61956) permit unauthenticated remote attackers to manipulate weather parameters, runway settings, and extract sensitive meteorological data via missing authentication controls and exposed credentials. Exploitation could disrupt airport operations, mislead air traffic control and pilots, and create hazardous flight conditions by disabling vital alerts or injecting false data. The vulnerabilities were reported by a security researcher and were assigned the highest CVSS score of 10.0, reflecting severe risk to operational safety. This incident highlights the escalating risk facing critical infrastructure as attackers increasingly target operational technology systems with low-complexity, high-impact exploits. Given the global reliance on secure flight operations, the breach underscores the urgency for robust authentication, segmentation, and credential management controls across transportation-critical systems.
8 months ago
Kill Chain
2024 Mega Email Stealer Log Breach: Over 2 Billion Accounts Exposed
In early June 2024, a large-scale data breach involving the exposure of over 2 billion email addresses was discovered in a massive stealer log dataset. Attackers compiled these emails through widespread info-stealer malware campaigns, collecting credentials and sensitive data from compromised systems and aggregating them into searchable logs accessible on illicit forums. The breach, prepared for public release after extensive validation and costly processing, highlights the sheer scale and complexity of modern info-theft operations. Affected users may face targeted phishing, credential stuffing attacks, and long-term privacy risks due to the availability of this data. This breach exemplifies the accelerating trend of industrialized data theft and commoditization of stolen information, especially as info-stealer malware campaigns proliferate and cybercriminals refine monetization methods. Organizations should be on heightened alert for downstream risks, including targeted attacks leveraging exposed data and regulatory scrutiny of data protection practices.
8 months ago
Kill Chain
Qantas 2024 Data Breach: Legal Orders Fail, Security Controls Critical
In early 2024, Qantas Airways experienced a significant data breach when cybercriminals exfiltrated sensitive passenger and employee information. Despite an Australian court issuing an injunction to prevent the distribution of stolen data, the responsible threat actors ignored the legal order and leaked the compromised datasets on the dark web. The breach was confirmed by multiple data breach notification services. Attackers leveraged unencrypted traffic vulnerabilities and lateral movement inside Qantas systems, bypassing internal controls and highlighting deficiencies in east-west traffic security and zero trust segmentation. Business operations faced regulatory pressure, reputational damage, and potential compliance issues. This incident underscores the difficulties organizations face in containing modern breaches, especially as legal measures alone cannot halt the distribution or misuse of exposed data. The continued release and trade of stolen datasets emphasize the importance of proactive technical controls and the need for robust, automated detection and data governance in line with evolving compliance standards.
8 months ago
Kill Chain
Clop Breaches Envoy Air via Oracle EBS Zero-Day in 2025: Key Lessons in Ransomware Defense
In October 2025, Envoy Air, a regional subsidiary of American Airlines, confirmed that attackers compromised business information from its Oracle E-Business Suite (EBS) application. The Clop ransomware/extortion group exploited a newly discovered Oracle EBS zero-day (CVE-2025-61882) to access internal systems in August 2025. Upon discovery, Envoy initiated an investigation, notifying law enforcement and confirming that no sensitive customer or employee data was affected, though limited business and commercial contact details were exposed. This incident underscores the rising trend of ransomware and extortion groups leveraging zero-day vulnerabilities in key enterprise platforms. The Clop gang continues to target multiple industries through advanced attacks on widely used software, emphasizing the urgent need for robust patch management, east-west traffic security, and zero trust segmentation strategies.
8 months ago
Kill Chain
Satellite Communications Exposed: 2025’s Unencrypted Data Crisis
In mid-2025, a landmark study revealed that a vast portion of global geostationary satellite communications—including critical infrastructure, government, corporate, and consumer data—are transmitted unencrypted. Security researchers, using inexpensive commercially available satellite equipment, intercepted highly sensitive transmissions such as internal communications, private calls and SMS, and in-flight internet traffic. Because thousands of geostationary transponders broadcast across enormous geographic areas, these unprotected signals can be passively accessed by unauthorized parties from virtually anywhere within satellite coverage zones, putting confidential data at significant risk of interception and exploitation. This incident underscores a persistent and growing concern regarding the lack of robust encryption in satellite communications, even as regulations and cyber threats evolve rapidly. Increasing satellite connectivity for aviation, maritime, and remote access drives urgency around encryption, as adversaries and data brokers exploit these vulnerabilities on a global scale.
8 months ago
Kill Chain
Startling Satellite Breach: How $600 Unlocked a Global Data Leak in 2025
In early 2025, researchers from the University of Maryland and UC San Diego revealed widespread leakage of sensitive and private data—including military and telecom communications—through unencrypted transmissions sent over geostationary (GEO) satellites. By using only $600 in commercially available equipment, the team passively intercepted vast amounts of plaintext data from major organizations, government entities, and telecom users around the globe. The incident highlighted fundamental lapses in network-layer encryption practices, allowing phone calls, SMS messages, internal application data, and even military vessel information to leak with no authentication or protection. The research further demonstrated that even technically unsophisticated actors could compromise critical satellite backhaul links using minimal resources. This event underscores the urgent need for end-to-end encryption and robust monitoring of satellite communications as reliance on these channels increases and barriers to interception continue to fall. Government and industry must now address the rapidly evolving risk landscape, especially as critical infrastructure becomes more dependent on satellite connectivity.
8 months ago
Kill Chain
Qantas 2025 Data Breach: Scattered LAPSUS$ Defies Legal Barriers
In October 2025, Australian airline Qantas suffered a major data breach when threat actor group Scattered LAPSUS$ released sensitive customer and employee data following an extortion attempt. Despite Qantas obtaining a legal injunction aimed at stopping the dissemination of the information, the attackers proceeded to publish the stolen data, rendering legal intervention ineffective. The incident exposed personal records and travel information, spotlighting ongoing organizational vulnerabilities to data extortion and public leaks driven by sophisticated attackers exploiting access. The breach prompted widespread media coverage and concern over enforcement power in digital incidents. This attack underscores the growing trend of double extortion tactics, where attackers threaten to release stolen data for leverage, outpacing regulatory or legal controls. The event exemplifies the surge in ransomware and extortion methods targeting aviation and critical infrastructure, reinforcing the urgent need for proactive, technical mitigations and incident preparedness planning.
8 months ago
Kill Chain
Inside the Qantas 2025 Ransomware Breach: Why Legal Measures Can’t Stop Data Leaks
In October 2025, Qantas, the Australian airline, suffered a ransomware attack attributed to the 'Scattered LAPSUS$ Hunters' group. Attackers claimed to have breached Qantas’ systems via a supply chain vulnerability, exfiltrating personal and loyalty program data of potentially hundreds of thousands of customers, including high-profile individuals. After initial extortion attempts, the stolen data—including names, emails, and frequent flyer records—was publicly leaked when Qantas refused to pay ransom. Qantas took legal steps, securing a court injunction to limit data dissemination, but these measures proved ineffective at curbing the spread among criminal and international actors. This breach highlights the ongoing threat of ransomware and data extortion campaigns targeting major brands, frequently leveraging supply-chain infiltration and cloud-based service weaknesses. The incident also underscores the limited real-world efficacy of legal remedies like injunctions, as well as evolving attacker strategies involving public shaming and mass data exposure.
8 months ago
Kill Chain
Salesforce Breach 2024: Scattered Lapsus$ Hunters' Massive Data Extortion Campaign
In October 2024, the cybercriminal collective Scattered Lapsus$ Hunters resurfaced with a dedicated leak site, threatening to publish stolen data related to Salesforce customers if their extortion demands were not met. This group, an alliance of threat actors including Scattered Spider, Lapsus$, and ShinyHunters, allegedly compromised Salesforce environments through social engineering—specifically vishing IT support personnel to obtain credentials and, in parallel campaigns, exploiting OAuth token theft. The attackers claimed to possess approximately one billion records from 39 prominent organizations, including sensitive personally identifiable information (PII) like Social Security and driver’s license numbers. This incident underscores the increased targeting of SaaS platforms via identity and access manipulation, as well as the growing sophistication of multinational threat actor collaborations. It signals elevated risk for organizations relying on cloud applications and highlights the necessity of enforcing multi-factor authentication and vigilant third-party access controls.
8 months ago
Kill Chain
WestJet 2025 Data Breach: How Social Engineering and Remote Access Led to Massive Data Exposure
In June 2025, Canadian airline WestJet suffered a major data breach affecting approximately 1.2 million customers. Threat actors exploited social engineering to reset an employee’s password, gaining access through Citrix systems and compromising both Windows and Microsoft cloud networks. The attackers were able to exfiltrate sensitive personal data, including full names, dates of birth, physical addresses, passport or government IDs, travel information, rewards member data, and select customer service interactions. While no credit card numbers or passwords were disclosed, the incident required investigation by law enforcement and forced WestJet to notify affected users and authorities across North America, offering free identity monitoring. This breach highlights the growing effectiveness of identity-based attacks, particularly those leveraging social engineering to bypass traditional security controls via remote access platforms. With aviation and travel industries increasingly targeted, this incident underscores the urgent need for modern Zero Trust approaches and continuous monitoring of east-west traffic within enterprise networks.
8 months ago
Kill Chain
WestJet Data Breach 2025: Passport Info Exposed in Major Airline Cyberattack
In June 2025, Canadian airline WestJet revealed a cybersecurity breach that resulted in the exposure of sensitive customer information, including names, dates of birth, mailing addresses, travel documents such as passports and government IDs, requested accommodations, complaints, and loyalty program data. The breach, disclosed after disruptions to internal systems and the company’s mobile app, was investigated over several months, with findings confirmed in mid-September. While no official attribution has been confirmed, the notorious Scattered Spider threat group was active in targeting the aviation industry at the time. The FBI is assisting with the investigation, and all affected customers have been notified. This breach is of significant concern as it exemplifies the intensifying targeting of travel and aviation sectors by sophisticated threat actors using advanced social engineering and credential-harvesting techniques. The incident also underscores increasing regulatory scrutiny and customer awareness around identity-related attacks and privacy risks in critical infrastructure industries.
8 months ago
Kill Chain
RTX Ransomware Attack Disrupts Major European Airports in 2025
In September 2025, RTX Corporation (formerly Raytheon Technologies) experienced a significant ransomware attack targeting its Collins Aerospace Multi-User System Environment (MUSE) passenger processing platform. The ransomware—suspected to be from the Hardbit or Loki ransomware families—caused widespread operational disruptions, leading to flight cancellations and delays at major European airports including London Heathrow, Brussels, Cork, Dublin, and Berlin. The attack was detected on September 19th, prompting RTX to initiate a full incident response, notify authorities, and deploy technical mitigations across affected customer networks. Law enforcement arrested a UK-based suspect linked to the attack, underscoring the event’s criminal intent and sophistication. This incident highlights a rising trend of ransomware groups targeting critical infrastructure and supply chain applications, often by leveraging commodity Ransomware-as-a-Service (RaaS) tools. It also signals a shift in attacker behavior towards less sophisticated malware, which can still yield significant operational disruption due to integrated, shared technology platforms in aviation and other sectors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports