Cyberattack on Salt Lake City International Airport Exposes Gaps in Governance and Security
In December 2024, Salt Lake City International Airport (SLCIA) Utah’s largest transportation hub fell victim to a cyberattack targeting its system controls, including ventilation and paging networks. According to a 2025 state legislative audit, attackers compromised multiple administrator accounts, deployed ransomware, and attempted to exfiltrate sensitive data before Utah Cyber Center and city IT teams intervened. While officials described the impact as "minimal," with no personal data stolen, the incident exposed significant vulnerabilities in the airport’s cybersecurity defenses.
The audit, requested by state officials months after the attack, found that SLCIA’s pre-incident security controls were "insufficient" and failed to meet federal Transportation Security Administration (TSA) guidelines. Though the city claims compliance with three of four TSA-recommended practices, auditors noted that leadership and governance failures including poor coordination between divisions directly contributed to unaddressed risks. A newly implemented cybersecurity tool, funded by federal and state resources, helped detect the attack, but experts from the Utah Education and Telehealth Network concluded that the airport remains "lagging" in risk mitigation.
Key findings from the audit include:
- Leadership shortcomings enabled persistent vulnerabilities, with inadequate oversight of IT and maintenance needs.
- Governance gaps hindered internal audit effectiveness and cross-division collaboration.
- Vendor-related risks and a lack of systematic risk assessments left critical systems exposed.
Auditors issued four recommendations, urging SLCIA to adopt best practices for vendor risk management, establish regular risk assessments, enforce accountability for division directors, and improve reporting to city leadership. While acknowledging "meaningful steps" toward improvement, the report warns that gaps in governance and risk management persist, posing ongoing threats to operations and the state’s economy.
Salt Lake City officials partially concurred with the findings, citing progress in strengthening protocols and accountability. However, they criticized the audit for focusing on leadership criticism rather than actionable security insights, arguing the report lacked clarity on current readiness. The city also noted delays in receiving third-party review findings, which hindered timely implementation of recommendations.
Utah Auditor General Kade Minchey countered that the city’s response downplayed leadership accountability, emphasizing that systemic improvements not scope limitations are necessary to prevent future disruptions. The standoff underscores tensions between state oversight and local efforts to bolster cybersecurity in a rapidly evolving threat landscape.
Salt Lake City International Airport cybersecurity rating report: https://www.rankiteo.com/company/slc-international-airport
"id": "SLC1781655959",
"linkid": "slc-international-airport",
"type": "Ransomware",
"date": "12/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Transportation/Aviation',
'location': 'Salt Lake City, Utah, USA',
'name': 'Salt Lake City International Airport (SLCIA)',
'size': 'Utah’s largest transportation hub',
'type': 'Airport'}],
'attack_vector': 'Compromised administrator accounts',
'data_breach': {'data_exfiltration': 'Attempted but not confirmed',
'personally_identifiable_information': 'No personal data '
'stolen',
'sensitivity_of_data': 'High (system controls data)',
'type_of_data_compromised': 'Sensitive data (attempted '
'exfiltration)'},
'date_detected': '2024-12',
'date_publicly_disclosed': '2025',
'description': 'In December 2024, Salt Lake City International Airport '
'(SLCIA) fell victim to a cyberattack targeting its system '
'controls, including ventilation and paging networks. '
'Attackers compromised multiple administrator accounts, '
'deployed ransomware, and attempted to exfiltrate sensitive '
'data before intervention by Utah Cyber Center and city IT '
'teams. The incident exposed significant vulnerabilities in '
'the airport’s cybersecurity defenses and governance gaps.',
'impact': {'brand_reputation_impact': 'Exposure of cybersecurity '
'vulnerabilities',
'data_compromised': 'Sensitive data (exfiltration attempted but '
'not confirmed)',
'operational_impact': 'Minimal (according to officials)',
'systems_affected': ['Ventilation networks', 'Paging networks']},
'investigation_status': 'Completed (audit findings published)',
'lessons_learned': 'The incident highlighted leadership shortcomings, '
'governance gaps, vendor-related risks, and the need for '
'systematic risk assessments and improved accountability.',
'post_incident_analysis': {'corrective_actions': ['Implementation of a new '
'cybersecurity tool',
'Progress in strengthening '
'protocols and '
'accountability'],
'root_causes': ['Leadership shortcomings',
'Governance gaps',
'Inadequate oversight of IT and '
'maintenance needs',
'Vendor-related risks',
'Lack of systematic risk '
'assessments']},
'ransomware': {'data_encryption': 'Yes', 'data_exfiltration': 'Attempted'},
'recommendations': ['Adopt best practices for vendor risk management',
'Establish regular risk assessments',
'Enforce accountability for division directors',
'Improve reporting to city leadership'],
'references': [{'source': 'State legislative audit (2025)'}],
'regulatory_compliance': {'regulations_violated': 'Failed to meet federal '
'Transportation Security '
'Administration (TSA) '
'guidelines'},
'response': {'containment_measures': 'Intervention by city IT teams',
'enhanced_monitoring': 'Newly implemented cybersecurity tool',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Implementation of a new cybersecurity '
'tool (federally and state-funded)',
'third_party_assistance': 'Utah Cyber Center, Utah Education and '
'Telehealth Network'},
'title': 'Cyberattack on Salt Lake City International Airport',
'type': 'Ransomware Attack',
'vulnerability_exploited': 'Insufficient security controls, governance gaps, '
'vendor-related risks'}