Everest, a ransomware group, listed flydubai, a Dubai-based low-cost airline, on its dark web leak site and threatened to publish what it described as stolen employee records and Boeing software, according to Cybernews.
The group had not released data samples to substantiate its allegations when the report appeared.
Everest alleged that it stole 4.36GB of data, including 17,053 personnel records concerning 2,862 employees. The purported records cover pilots, cabin crew, training managers, dispatchers and ground staff.
The records reportedly date from 2009 to 2020 and contain employee names, identification numbers, job titles, employment dates and training qualifications. Everest’s leak-site listing also displayed a six-day timer for negotiations, Cybernews reported.
Boeing software among claimed files
The alleged dataset extends beyond employee information. Everest said it possessed a complete Boeing 737 Next Generation interactive training course, including thousands of lessons, animations, audio narration and assessments covering aircraft systems and operational procedures.
Everest also claimed to have obtained an installation package for Boeing’s Performance Engineers Tool (PET 3.2), software used to calculate takeoff weights, landing distances, fuel requirements and obstacle clearance.
According to the attackers’ description reported by Cybernews, the alleged dataset included 2,827 Java source-code files, more than 2,000 purportedly marked as Boeing proprietary, confidential or trade-secret material.
If authentic, the alleged source-code files could expose Boeing intellectual property. Everest’s description, however, does not establish that Boeing code was stolen or that either company’s operational systems were compromised.
Employee data creates phishing risks
Cybernews researchers warned that the personnel records, if genuine, could enable targeted phishing and social engineering attacks. Information about an employee’s position, training history and qualifications could help attackers create convincing messages impersonating airline personnel or internal departments.
On the alleged attack, Dray Agha, senior manager of tactical response at cybersecurity firm Huntress said that ransomware groups typicall exaggerate their stolen data to pressure victims into paying.
“We advise treating unverified claims with caution until actual data samples appear. If this group has genuinely acquired Boeing engineering software and airline pilot records, the privacy and operational impacts are significant. Aviation organisations must secure their administrative networks with the exact same rigour they apply to critical flight systems,” Agha added.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in its ransomware and data-extortion guidance, recommends determining which systems were affected, investigating possible data exfiltration and assessing notification obligations. CISA also notes that criminals may threaten to release stolen information without encrypting systems.