Notorious Hackers Target US Airlines as Scattered Spider Gang Goes After Major Carriers -->

Notorious Hackers Target US Airlines as Scattered Spider Gang Goes After Major Carriers

Jumat, 27 Juni 2025, Juni 27, 2025

App software ID editors choose and evaluate products. independently If you make purchases via these affiliate links, we might receive commissions, aiding in supporting us. testing .

With the surge in summer travel, airlines are encountering an additional issue besides congested terminals: a well-known hacker organization has broadened its focus to include the aviation sector.

On Friday, cybersecurity professionals alerted that the cyber gang Scattered Spider is targeting airlines and transportation companies, following Hawaiian Airlines' announcement of a recent cyber attack. Earlier in the month, Canadian carrier WestJet was similarly affected. reported a cyber incident.

Mandiant, Google’s cybersecurity division, has reported being "currently cognizant of several occurrences within the aviation industry that bear similarities to Scattered Spider," as stated by their lead analyst, John Hultquist. tweeted .

Scattered Spider grabbed headlines in 2023 for hacking MGM Resorts, which led to a major IT outage at the casino. US law enforcement later charged five suspects of the hacking group. But since then, the gang has returned, targeting retailers, insurance providers , and now airlines.

The Scattered Spider group has distinguished itself from other cybercrime organizations due to the distinctiveness of its members. native-English The group is particularly skilled at employing social engineering techniques, like pretending to be IT support personnel, to deceive company employees into providing password access or installing malware. remote access software on their computers. The goal is to steal confidential data and install ransomware To blackmail victim companies into paying millions in exchange.

Consequently, "the sector needs to tighten security measures for their call centers where this actor has achieved significant success through social engineering tactics," according to Hultquist.

The cybersecurity firm Palo Alto Networks has observed Scattered Spider focusing their efforts on the aviation sector as well. This was shared via LinkedIn. post SVP Sam Rubin highlighted that airline service providers must be cautious of "unusual" multi-factor authentication requests. This precaution is necessary since Scattered Spider has reportedly sent counterfeit SMS texts mimicking login systems to deceive staff members into providing their credentials.

Furthermore, U.S. cybersecurity agencies have noticed this group employing brute-force techniques by overwhelming a firm’s authentication mechanism with an incessant stream of push notifications. Their aim is to confuse or frustrate potential targets into inadvertently granting them permission to access their accounts.

As a reaction to the threat, Mandiant Chief Technology Officer Charles Carmakal responded. wrote on LinkedIn: “We recommend that the industry immediately take steps to tighten up their help desk identity verification processes prior to adding new phone numbers to employee/contractor accounts (which can be used by the threat actor to perform self-service password resets).”

Up until now, Hawaiian Airlines and WestJet have not verified whether Scattered Spider is responsible for the two cyberattacks. However, Hawaiian Airlines stated in a statement We remain committed to operating our complete flight schedule securely, and travelers' journeys are unaffected.

TerPopuler