Ukrainian Cyber Attack Grounds Russia’s Largest Airline
Overview of the Incident
In a significant cybersecurity breach, Ukraine’s pro-Ukrainian hacking group known as Silent Crow has successfully targeted Aeroflot, Russia’s largest airline. This strategic assault has led to a series of flight cancellations and operational disruptions affecting air travel across Russia.
Details of the Cyber Attack
Silent Crow made an announcement via Telegram, revealing that the group had not only stolen vital data but also compromised and dismantled Aeroflot’s internal systems. The post highlighted the culmination of a prolonged operation that involved infiltrating the airline’s IT infrastructure methodically.
Inside Information and Data Compromise
The group disclosed they gained extensive access to Aeroflot’s corporate network, stating, “For a year, we were inside their corporate network, methodically developing access.” Their infiltration allowed them to access full flight history databases and critical corporate systems such as CREW, Sabre, SharePoint, and more.
They reported having taken control of personal devices held by employees, including those of senior management. In addition, they indicated that they acquired sensitive information, including recordings from wiretapping servers. The scale of the breach was staggering, with the group claiming to have affected 7,000 servers, both physical and virtual.
Volume of Data Stolen
According to Silent Crow, they exfiltrated a massive amount of data totaling 12 terabytes of databases, 8 terabytes of files from Windows Share, and 2 terabytes of corporate email. Their message underscored the enormity of the breach: “All these resources are now inaccessible or destroyed; recovery will require, possibly, tens of millions of dollars.”
Impact on Aeroflot Operations
As a direct result of the cyber attack, the Russian Prosecutor General’s Office stated that Aeroflot experiences significant operational delays. Reports indicate that at least 80 flights were delayed and around 60 flights were canceled, with some sources suggesting that the total number of canceled flights exceeded 100. Aeroflot’s website also faced disruptions during this period, facing downtime before being restored, albeit with frequent error messages.
The Threat to Cyber Defenses
Silent Crow did not stop at the act of destruction; they issued a warning to Russian cyber defense agencies, claiming that these entities were unable to protect their critical infrastructure from such attacks. The hackers stated they had been under surveillance, promising to publish further data in the future as a follow-up to this operation.
Implications for Passenger Data
The hacking group asserted that the personal data of all Russians who have ever flown with Aeroflot has been compromised in the breach. In a sharp jab at the airline, they remarked that this data had “gone on a trip – albeit without luggage and one way.”
Conclusion of the Incident
The ramifications of this cyber attack extend beyond immediate operational issues. Aeroflot faces not just financial implications from operational disruptions but also the long-term impacts related to compromised data security. As the airline works to restore normal operations, the fallout from this incident continues to surface, revealing the growing cyber warfare landscape between nations.


