Rampant cybercriminal group targets US airlines
A notorious cybercriminal group has shifted its attention to the aviation industry, successfully breaching the computer networks of multiple airlines in the United States and Canada this month, according to the FBI and private experts responding to the hacks.
The hacking hasn't affected airline safety, but it has top cyber executives at major airlines across the United States on alert because of the hacking suspects: A network of young cybercriminals called 'Scattered Spider' who are known for their aggressive efforts to extort or embarrass their victims.
It's a fresh headache for the travel industry as the busy summer travel season kicks into high gear. This is now the third major US business sector in the last two months, after insurance and retail, to face a flurry of cyberattacks tied to the criminal group.
The hackers target big companies and their IT contractors, 'which means anyone in the airline ecosystem, including trusted vendors and contractors, could be at risk,' the FBI said Friday night in a statement that named Scattered Spider as the perpetrator of the airline hacks. 'Once inside (a victim's network), Scattered Spider actors steal sensitive data for extortion and often deploy ransomware,' the FBI said.
The FBI, the statement continued, 'is actively working with aviation and industry partners to address this activity and assist victims.'
Hawaiian Airlines and Canada's WestJet confirmed this week that they were still assessing the fallout from recent cyberattacks, though the airlines did not name the perpetrators. More victims in the aviation industry could come forward, sources briefed on the investigation said.
WestJet's issues began two weeks ago, when the airline said it was responding to a 'cybersecurity incident' that was affecting access 'to some services and software systems,' including its app for customers. Both WestJet and Hawaiian Airlines said their operations were unaffected by the hacks.
The lack of impact on operations at the airlines is 'likely a sign of good internal network separations or good business continuity and resiliency planning,' said Aakin Patel, the former chief information security officer of Las Vegas' main airport.
It is not just the airlines themselves, but other 'segments of the aviation ecosystem' that are seeing increased cyberattacks, according to Jeffey Troy, the president of the Aviation ISAC, an industry group for sharing cyber threats. 'Our members are keenly alert to attacks from financially motivated attackers and collateral impacts emanating out of geo-political tensions around the world,' Troy said in a statement to CNN.
The fine margins for error in the airline industry were on display Friday, when a separate IT outage, apparently unrelated to malicious cyber activity, caused delays for some American Airlines passengers.
The Scattered Spider hacks have mobilized people across the industry to respond. In-house cybersecurity experts at major airlines have been closely monitoring the situation, sources familiar with the response told CNN, while cybersecurity firms such as Google-owned Mandiant are helping with the recovery and urging airlines to secure their customer service call centers.
One of Scattered Spiders' preferred methods of infiltrating corporations is calling up help desks and pretending to be employees or customers. The technique has been highly effective for hackers to gain access to the networks of big companies.
'Airlines rely heavily on call centers for a lot of their support needs,' Patel told CNN, making them 'a likely target for groups like this.'
Scattered Spider gained attention in September 2023 when they were linked to a pair of multimillion-dollar hacks on Las Vegas casinos and hotels MGM Resorts and Caesars Entertainment. The hackers tend to pick one sector to target for weeks on end. Earlier this month, they were the suspect in a hack of insurance giant Aflac that potentially stole Social Security numbers, insurance claims and health information. Before that, it was the retail sector: The hackers, according to an internal memo obtained by CNN, targeted Ahold Delhaize USA, which has the same parent company as the Giant and Food Lion grocery chains.
'The actor's core tactics, techniques, and procedures have remained consistent,' Mandiant chief technology officer Charles Carmakal said Friday in a statement, and that it 'is aware of multiple incidents in the airline and transportation sector' that resemble the operations of Scattered Spider.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CBS News
13 minutes ago
- CBS News
Surveillance video shows suspect breaking into 2 Boston restaurants and smashing cash registers
Person seen breaking into Boston restaurants and stealing cash from register Person seen breaking into Boston restaurants and stealing cash from register Person seen breaking into Boston restaurants and stealing cash from register Boston Police are investigating two break-ins that happened at restaurants in Boston's West Fens neighborhood on Sunday morning. It happened around 4 a.m. on Peterboro Street. Police received the reports of the robberies around 8:30 a.m. The two restaurants were Rod Thai Family Taste and Viva Burrito. Surveillance video shows the burglar breaking into Viva Burrito. The suspect can be seen throwing something through the front glass door of the Mexican restaurant before ducking inside. The suspect smashed the register on the ground until it opened. Viva Burrito Once they got inside, they grabbed the cash register and began repeatedly smashing it on the ground until it broke open. An undisclosed amount of money was taken from both businesses, according to police. Boston Police are still investigating the break-ins. They say that no arrests have been made in connection with this case. Restaurant owners shocked by break-ins Panda Limsawat's family owns Rod Thai Family Taste. When he arrived at work, he saw that the front door of the business had been shattered. "I was shocked," he said. "They took the money. Just the money. And it's like they threw the register to the floor." "I never think about it that it was going to happen to us," Limsawat said. But now that it has, he has one message for the suspect: "It's not good to do this or steal anyone's money," he said. Both Rod Thai Family Taste and Viva Burrito were open and serving customers later in the day on Sunday. contributed to this report.


CNN
17 minutes ago
- CNN
Canada will rescind a digital services tax to restart US trade talks
Canada will rescind a digital services tax – a way of taxing online companies – its government said on Sunday, in a bid to restart trade negotiations with the United States. US President Donald Trump on Friday canceled trade talks between the two countries, blaming the tax that he called 'a direct and blatant attack on our Country.' In a statement Sunday night, the Canadian government said it was stepping back from the tax to help bring the countries back to the table. 'To support those negotiations, the Minister of Finance and National Revenue, the Honourable François-Philippe Champagne, announced today that Canada would rescind the Digital Services Tax (DST) in anticipation of a mutually beneficial comprehensive trade arrangement with the United States,' according to the statement. 'Consistent with this action, Prime Minister Carney and President Trump have agreed that parties will resume negotiations with a view towards agreeing on a deal by July 21, 2025.' Digital services taxes are a way for countries to tax online services, in contrast to taxes on physical products. This is a developing story and will be updated.


CBS News
21 minutes ago
- CBS News
NYPD hunting for suspect in stabbing death of Bronx mother of 2
There is shock and disbelief in a Bronx neighborhood following the fatal stabbing of a mother of two. Police sources say victim knew the suspect. Here's the latest on the investigation Officers entered and exited an apartment building at 667 East 232nd St. in shifts on Sunday, less than 24 hours after first responders arrived on the scene and found 40-year-old Tamara Rowe with stab wounds to the chest and right arm. Officials say she died at the hospital. "I just saw like a whole bunch of police. I saw the ambulance," neighbor Tasha Shaw said. "To know that she was murdered in her apartment, it's sad." Police officers stood outside of the apartment door where blood stains marked a gruesome confrontation. Police sources called it a case of domestic violence, saying Rowe's partner stabbed her. Police at the scene said investigators confiscated surveillance video showing a man fleeing the apartment building using the stairs. "That's really scary to know that he or she is on the loose," Shaw said. Neighbors describe victim as loving and hardworking mom Other neighbors who knew Rowe asked to remain anonymous. "I was just shocked because she is a cool lady. Like, she doesn't seem to be someone that would be in any problems," one said. Residents described Rowe as quiet, calm, respectful and hardworking. Just down the hall, a friend who didn't want to be identified said he was destroyed by the news, adding Rowe was an excellent mother and that she lived in the apartment for about four years with the father of her two girls. He said he never saw them argue or be in a dispute. Anyone with any information is asked to call the NYPD's Crime Stoppers hotline at 1-800-577-TIPS (8477), or for Spanish, 1-888-57-PISTA (74782). You can also submit a tip via their website or via DM on Twitter, @NYPDTips. All calls are kept confidential.