Russia’s Largest Airline Grounds Dozens of Flights After Ukrainian Cyber Attack

Published:

spot_img

Ukrainian Cyber Attack Grounds Russia’s Largest Airline

Overview of the Incident

In a significant cybersecurity breach, Ukraine’s pro-Ukrainian hacking group known as Silent Crow has successfully targeted Aeroflot, Russia’s largest airline. This strategic assault has led to a series of flight cancellations and operational disruptions affecting air travel across Russia.

Details of the Cyber Attack

Silent Crow made an announcement via Telegram, revealing that the group had not only stolen vital data but also compromised and dismantled Aeroflot’s internal systems. The post highlighted the culmination of a prolonged operation that involved infiltrating the airline’s IT infrastructure methodically.

Inside Information and Data Compromise

The group disclosed they gained extensive access to Aeroflot’s corporate network, stating, “For a year, we were inside their corporate network, methodically developing access.” Their infiltration allowed them to access full flight history databases and critical corporate systems such as CREW, Sabre, SharePoint, and more.

They reported having taken control of personal devices held by employees, including those of senior management. In addition, they indicated that they acquired sensitive information, including recordings from wiretapping servers. The scale of the breach was staggering, with the group claiming to have affected 7,000 servers, both physical and virtual.

Volume of Data Stolen

According to Silent Crow, they exfiltrated a massive amount of data totaling 12 terabytes of databases, 8 terabytes of files from Windows Share, and 2 terabytes of corporate email. Their message underscored the enormity of the breach: “All these resources are now inaccessible or destroyed; recovery will require, possibly, tens of millions of dollars.”

Impact on Aeroflot Operations

As a direct result of the cyber attack, the Russian Prosecutor General’s Office stated that Aeroflot experiences significant operational delays. Reports indicate that at least 80 flights were delayed and around 60 flights were canceled, with some sources suggesting that the total number of canceled flights exceeded 100. Aeroflot’s website also faced disruptions during this period, facing downtime before being restored, albeit with frequent error messages.

The Threat to Cyber Defenses

Silent Crow did not stop at the act of destruction; they issued a warning to Russian cyber defense agencies, claiming that these entities were unable to protect their critical infrastructure from such attacks. The hackers stated they had been under surveillance, promising to publish further data in the future as a follow-up to this operation.

Implications for Passenger Data

The hacking group asserted that the personal data of all Russians who have ever flown with Aeroflot has been compromised in the breach. In a sharp jab at the airline, they remarked that this data had “gone on a trip – albeit without luggage and one way.”

Conclusion of the Incident

The ramifications of this cyber attack extend beyond immediate operational issues. Aeroflot faces not just financial implications from operational disruptions but also the long-term impacts related to compromised data security. As the airline works to restore normal operations, the fallout from this incident continues to surface, revealing the growing cyber warfare landscape between nations.

spot_img

Related articles

Recent articles

Atlassian Rovo Vulnerability Allows Data Exfiltration from Jira and Confluence

Recent findings have revealed a vulnerability in Atlassian's Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was...

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists. The State Security Service of Georgia has initiated a criminal investigation into a purported disinformation...

Untrusted Data Safety

Microsoft Defender’s attack disruption now includes device isolation, a new response action that enhances protection for compromised endpoints. This capability was recently highlighted in...