Boeing investigating leaked data after LockBit allegedly publishes stolen info

Omega Balla
Airplane maker Boeing said it is investigating data leaked by a prominent Russia-based ransomware gang that was allegedly stolen from the company.

Airplane maker Boeing said it is investigating data leaked by a prominent Russia-based ransomware gang that was allegedly stolen from the company.

Two weeks ago, the aviation manufacturing giant confirmed that its parts and distribution business was affected by a cyberattack.

On Friday, the LockBit ransomware gang published 50GB of information it allegedly stole from the company after days of adding and removing the company from its leak site. The gang made several unverified claims that it was negotiating a ransom with Boeing before talks fell through.

In a statement to Recorded Future News on Monday, Boeing said it would notify anyone whose information may have been leaked.

“Elements of Boeing’s parts and distribution business recently experienced a cybersecurity incident. We are aware that, in connection with this incident, a criminal ransomware actor has released information it alleges to have taken from our systems,” a spokesperson said.

“We continue to investigate the incident and will remain in contact with law enforcement, regulatory authorities, and potentially impacted parties, as appropriate. We remain confident this incident poses no threat to aircraft or flight safety.”

Data shared by LockBit actors indicates the group may have exploited CVE-2023-4966 — a recently disclosed vulnerability known colloquially as “Citrix Bleed” — in its attack on Boeing.

Several cybersecurity experts praised Boeing for not buckling and paying the ransom.

“Refusing to pay a ransom is the right thing to do. If everyone followed Boeing’s path, ransomware ROI would become an uneconomical vector, and eventually cease to exist,” said Coro co-founder Dror Liwer.

LockBit continues to cause untold damage to organizations across the world, far outpacing any other ransomware gang in terms of attacks launched. Last week, the Querétaro Intercontinental Airport confirmed it was dealing with a cyberattack the same LockBit ransomware hackers claimed to have targeted the airport.

The gang surpassed 2,000 attacks in recent months putting it more than 1,000 attacks ahead of the next closest group according to statistics from Recorded Future.

BriefsCybercrime
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Ransomware attack on Ohio city impacts multiple services

Next Post

FBI takes down IPStorm malware botnet as hacker behind it pleads guilty

Related Posts

OfflRouter Malware Evades Detection in Ukraine for Almost a Decade

Select Ukrainian government networks have remained infected with a malware called OfflRouter since 2015. Cisco Talos said its findings are based on an analysis of over 100 confidential documents that were infected with the VBA macro virus and uploaded to the VirusTotal malware scanning platform. "The documents contained VBA code to drop and run an executable with the name 'ctrlpanel.exe,'"
Avatar
Read More

Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign

A previously undocumented Chinese-speaking threat actor codenamed SneakyChef has been linked to an espionage campaign primarily targeting government entities across Asia and EMEA (Europe, Middle East, and Africa) with SugarGh0st malware since at least August 2023. "SneakyChef uses lures that are scanned documents of government agencies, most of which are related to various countries' Ministries
Avatar
Read More

Learn to Secure Petabyte-Scale Data in a Webinar with Industry Titans

Data is growing faster than ever. Remember when petabytes (that's 1,000,000 gigabytes!) were only for tech giants? Well, that's so last decade! Today, businesses of all sizes are swimming in petabytes. But this isn't just about storage anymore. This data is ALIVE—it's constantly accessed, analyzed, shared, and even used to train the next wave of AI. This creates a huge challenge: how do you
Avatar
Read More