Russia’s flagship carrier Aeroflot suffered a crippling cyberattack attributed to pro-Ukraine hacktivist groups Silent Crow and Cyber Partisans BY. This year-long breach culminated in the complete destruction of the airline’s internal IT infrastructure, causing severe operational paralysis, widespread flight cancellations, and the potential exposure of millions of passenger records.
The attackers infiltrated Aeroflot’s systems in mid-2024, maintaining covert access and systematically escalating privileges. Their final blow involved deploying a wiper payload that destroyed approximately 7,000 servers and exfiltrating over 20 TB of sensitive data, including passenger PII, emails, flight logs, and internal communications.
Key operational impacts:
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.
This website uses the following additional cookies:
(List the cookies that you are using on the website here.)
More information about our Cookie Policy