Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2023_097
A company specializing in civil and military aeronautics and providing services and products to [...]
Day Month Year Country Activity Incident Type
24 July 2023 United States Defence Virus/Ransomware

Summary

The victim is an important group of the aerospace and defense industry. It was reported to be hit by a ransomware group.

The attack could have resulted in the leak of over 20 GB of sensitive personal data belonging to pilots and ground staff associated with the partners of the victim from many parts of the world.

The victim initiated a comprehensive investigation, collaborating with cybersecurity experts and law enforcement agencies to contain the breach and mitigate potential damages and urged affected individuals to monitor their personal information, remain vigilant against phishing attempts, and report suspicious activity.

Victim

Collins Aerospace

Claimed/Reported Threat Actor

Bianlian

Origin

Cybercrime

Main impact

Availability

References

Recommendations to Defence to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Thursday, 10th October 2024.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2024.