The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Airlines/Aviation
Breach intelligence, attack campaigns, and threat reports targeting the Airlines/Aviation sector.
Explore Other Sectors
Airlines/Aviation Threat Reports
Teen Arrested in 2023 Las Vegas Casino Ransomware Attacks Linked to Scattered Spider
In late 2023, Las Vegas casinos suffered major cyberattacks attributed to the Scattered Spider threat group, resulting in widespread operational disruption. The attacks targeted MGM Resorts International and Caesars Entertainment, leveraging sophisticated social engineering and phishing tactics to gain network access, move laterally, and ultimately extort ransom payments. MGM reported losses exceeding $100 million, while Caesars reportedly paid $15 million to mitigate risks. In June 2024, a local teenage suspect was arrested in connection to these events, highlighting the involvement of young, native English-speaking cybercriminals and a broader international law enforcement response. This incident exemplifies the increasing prevalence of highly organized, technology-savvy ransomware and extortion campaigns that rely on social engineering and identity-centric attack vectors. Organizations across industries face rising risks as threat groups adopt coordinated, multifaceted tactics to exploit internal and hybrid cloud environments.
8 months ago
Kill Chain
Ransomware Attack Disrupts Major European Airports via Collins Aerospace in 2025
In September 2025, a major ransomware attack on Collins Aerospace, a critical provider of check-in and boarding systems, triggered widespread disruptions at several major European airports, including Heathrow, Brussels, and Berlin Brandenburg. The hackers targeted the Multi-User System Environment (MUSE) platform, which airlines rely on to coordinate check-in desks and gate assignments. As a result, more than 100 flights were delayed or cancelled, and thousands of passengers faced manual check-in procedures while airports scrambled to contain the operational fallout. Law enforcement and cybersecurity agencies are actively investigating, prioritizing the restoration of affected systems and mitigation of further impact. This incident underlines the escalating risk posed by ransomware targeting supply chain infrastructure and the aviation sector’s reliance on shared IT systems. It also reflects a broader trend of cybercriminals exploiting third-party service dependencies, bringing renewed urgency to layered defense strategies and zero-trust adoption for business-critical environments.
8 months ago
Kill Chain
Airport Check-In Disruption: 2024 Supply-Chain Breach at Heathrow
In June 2024, a major disruption struck multiple European airports, including London Heathrow, after a cyberattack targeted a third-party provider responsible for check-in kiosk software. The supply-chain attack led to widespread check-in outages, flight delays, and cancellations, impacting thousands of travelers over the weekend. Initial investigation suggests that attackers compromised the software vendor’s infrastructure—potentially with ransomware or through lateral movement via third-party access—causing operational downtime for airlines and airport operators relying on their services. The incident highlights growing dependency risks stemming from the use of specialized external IT vendors in critical national infrastructure, especially in aviation. This event underscores the accelerating trend of supply-chain attacks, where threat actors exploit weaker links outside direct company control. With aviation systems under heightened scrutiny and ransomware groups often targeting critical operations, organizations across sectors must reevaluate third-party security, segmentation, and visibility to mitigate cascading impacts from vendor compromises.
8 months ago
Kill Chain
2025 Retail Salesforce Data Heist: Extortion Attack Exposes Cloud Security Gaps
In mid-2025, a sophisticated data extortion campaign targeted high-end retail organizations leveraging Salesforce environments. Threat actors—identified as UNC6040 (responsible for access and reconnaissance) and Bling Libra (aka ShinyHunters, handling extortion)—gained initial access through voice-based phishing (vishing) techniques. After establishing a foothold, they conducted in-depth reconnaissance to collect sensitive customer data, including names, birthdates, contact details, and account metadata, which was then exfiltrated. The attackers threatened public disclosure unless the victim organizations paid a ransom, all while leaving minimal forensic traces due to a lack of malware deployment and custom tools. This incident highlights the increasing sophistication of financially motivated cybercrime operations and an industry-wide shift towards data theft extortion without ransomware. There is an urgent need for retail and cloud-reliant enterprises to reassess their security controls, as social engineering vectors bypass traditional perimeter defenses and regulatory scrutiny around cloud data protections intensifies.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports