Boeing and flydubai: Flydubai and Boeing: Targets of Everest Ransomware Campaign

Boeing and flydubai: Flydubai and Boeing: Targets of Everest Ransomware Campaign

Everest Ransomware Group Targets Flydubai and Boeing in Data Extortion Attack

The Russia-linked Everest ransomware group has claimed responsibility for a cyberattack targeting UAE-based airline flydubai, alleging the theft of 4.36GB of sensitive data including employee records, pilot training materials, and proprietary Boeing software. The breach, first reported on October 6, has been listed on the group’s dark web leak site, with a six-day negotiation deadline set for the affected organizations.

According to Everest, the stolen data includes 17,053 records spanning 2009 to 2020, containing personally identifiable information (PII) of 2,862 flydubai employees, such as full names, employee IDs, job titles, and training completion records. Cybersecurity experts warn that such data is highly monetizable for phishing and social engineering attacks.

In addition to employee records, the group claims to have obtained the installation package for Boeing’s Performance Engineers Tool (PET 3.2), a proprietary software used for takeoff weight calculations, fuel planning, and engine-out scenarios. Of the 2,800+ files allegedly stolen, around 2,000 are marked as "Boeing Proprietary, Confidential and/or Trade Secret." While the tool’s source code is considered less valuable for direct monetization, its exposure raises concerns about supply chain security and regulatory scrutiny, particularly from the European Union Aviation Safety Agency (EASA).

At the time of reporting, neither flydubai nor Boeing has publicly responded to the incident. Everest has not released data samples or screenshots to verify its claims, though the group has a history of high-profile extortion campaigns. Cybersecurity analysts describe the attack as "legitimate" and executed by an "experienced data extortion threat actor."

The breach underscores the growing risk of ransomware groups targeting aviation and aerospace sectors, where employee data, proprietary tools, and regulatory compliance intersect. The full impact of the incident remains unclear as negotiations proceed.

Source: https://cybermagazine.com/news/flydubai-boeing-targeted-by-everest

flydubai cybersecurity rating report: https://www.rankiteo.com/company/flydubai

Boeing cybersecurity rating report: https://www.rankiteo.com/company/boeing

"id": "FLYBOE1791541606",
"linkid": "flydubai, boeing",
"type": "Ransomware",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '2,862 employees',
                        'industry': 'Aviation',
                        'location': 'UAE',
                        'name': 'flydubai',
                        'type': 'Airline'},
                       {'industry': 'Aerospace, Aviation',
                        'location': 'Global',
                        'name': 'Boeing',
                        'type': 'Aerospace Manufacturer'}],
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '17,053 records',
                 'personally_identifiable_information': ['Full names',
                                                         'Employee IDs',
                                                         'Job titles',
                                                         'Training completion '
                                                         'records'],
                 'sensitivity_of_data': 'High (PII, proprietary, '
                                        'confidential/trade secret)',
                 'type_of_data_compromised': ['Employee records',
                                              'Pilot training materials',
                                              'Proprietary Boeing software']},
 'date_detected': '2023-10-06',
 'date_publicly_disclosed': '2023-10-06',
 'description': 'The Russia-linked Everest ransomware group has claimed '
                'responsibility for a cyberattack targeting UAE-based airline '
                'flydubai, alleging the theft of 4.36GB of sensitive data '
                'including employee records, pilot training materials, and '
                'proprietary Boeing software. The breach has been listed on '
                'the group’s dark web leak site with a six-day negotiation '
                'deadline.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': '4.36GB of sensitive data',
            'identity_theft_risk': 'High (PII exposure)',
            'legal_liabilities': 'Potential regulatory scrutiny (EASA)'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain, Data extortion',
 'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Everest'},
 'references': [{'date_accessed': '2023-10-06',
                 'source': 'Everest ransomware group dark web leak site'},
                {'source': 'Cybersecurity analysts'}],
 'regulatory_compliance': {'regulations_violated': ['Potential EASA '
                                                    'regulations']},
 'threat_actor': 'Everest ransomware group',
 'title': 'Everest Ransomware Group Targets Flydubai and Boeing in Data '
          'Extortion Attack',
 'type': 'Ransomware, Data Extortion'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.