Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Ransomware Group Leaks Files Allegedly Stolen From Boeing

The LockBit ransomware group has leaked gigabytes of files allegedly stolen from the systems of aerospace giant Boeing. 

Boeing Ransomware Attack

The notorious LockBit ransomware group has leaked gigabytes of files allegedly stolen from the systems of aerospace giant Boeing. 

LockBit recently named Boeing on its leak website, claiming that “a tremendous amount of sensitive data” has been stolen, but later removed the company from its site, saying that negotiations had started. 

Boeing was later once again added to the LockBit website and data allegedly stolen from its systems has now been leaked, indicating that the company has refused to pay a ransom. Over 40 Gb worth of archive and backup files are available for download. 

Boeing has confirmed that parts of its distribution business have been hit by a cyberattack. The aerospace giant is aware that a ransomware group has released information allegedly taken from its systems, but it has yet to share any information on the scope of the potential data breach. 

The company has reiterated that the cyber incident does not pose a threat to aircraft or flight safety.

The MalwareHunterTeam research group noted that many of the files appear to be associated with Aviall, a Boeing-owned aviation and aerospace component manufacturing company. Boeing acquired Aviall in 2006 and announced plans to retire the brand in 2020. 

“Question is how much the networks of the companies got merged in the past 17 years. Because if not too much and LockBit really only pwned the networks of Aviall, the problem is not very much bad, ‘simply’ bad for Boeing. But 17 years is a lot, so…,” MalwareHunterTeam wrote on X, formerly Twitter.

LockBit has been one of the most active ransomware groups, targeting organizations in various sectors and countries.

According to a report authored earlier this year by government agencies in North America, Europe, and Australasia, the group received $91 million in ransom payments from US organizations alone.

Advertisement. Scroll to continue reading.

Related: Air France, KLM Customers Warned of Loyalty Program Account Hacking

Related: Ransomware Attack on Aviation Services Firm Swissport Leads to Flight Delays

Related: Hundreds Stranded After Ransomware Attack on Indian Airline

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join us as we delve into the transformative potential of AI, predictive ChatGPT-like tools and automation to detect and defend against cyberattacks.

Register

As cybersecurity breaches and incidents escalate, the cyber insurance ecosystem is undergoing rapid and transformational change.

Register

Expert Insights

Related Content

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.

Ransomware

A SaaS ransomware attack against a company’s Sharepoint Online was done without using a compromised endpoint.

Ransomware

Several major organizations are confirming impact from the latest zero-day exploits hitting Fortra's GoAnywhere software.

Management & Strategy

Industry professionals comment on the recent disruption of the Hive ransomware operation and its hacking by law enforcement.

Data Breaches

KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.

Ransomware

US payments giant NCR has confirmed being targeted in a ransomware attack for which the BlackCat/Alphv group has taken credit.

Malware & Threats

Unpatched and unprotected VMware ESXi servers worldwide have been targeted in a ransomware attack exploiting a vulnerability patched in 2021.