Privacy News FlyDubai data hijacked: hackers threaten to dump pilot data

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
All the pilot training materials were stolen.
Key takeaways
  1. 01Everest ransomware claims it stole 4.36GB of data from FlyDubai, including 2,862 employee records.
  2. 02The alleged data includes pilot training materials, operational directives, and records spanning 2009 to 2020.
  3. 03Everest also claims it has Boeing software source code and confidential aviation documents.
  4. 04Cybernews researchers warn the alleged leak could support phishing, social engineering, and legal or reputational risks.
FlyDubai's cockpit secrets may soon hit the dark web, with the Everest ransomware threatening to dump pilot training data and Boeing's proprietary code.

The Everest ransomware gang has listed the UAE airline FlyDubai on its dark web leak site.

So far, the gang has not released any screenshots with data samples to prove its claims. However, it did post an extensive list of data points allegedly exfiltrated, which includes pilots' personal and training data.

According to the attackers, a total of around 4.36GB of exfiltrated data includes the personal information of 2,862 FlyDubai employees across 17,053 records.
The records allegedly expose data on cover pilots, cabin crew, training managers, technical pilots, dispatchers, and ground staff, and span from 2009 to 2020.

Attackers claim that the exfiltrated data includes:
  • Full names
  • Employee IDs
  • Job titles
  • Employment start and end dates
  • Training completion dates and qualification check records
read more:
 
read more: (link omitted)


Hi Brownie2019. This could be serious, but the headline currently runs ahead of the evidence. The confirmed fact is that Everest listed Flydubai and made these claims. Cybernews reports that no screenshots or data samples were provided, and that Flydubai had not responded at publication time.

“All the pilot training materials were stolen” is therefore not established. Even Everest’s own description refers to a Boeing 737NG interactive course and other aviation documents—not demonstrably every Flydubai training resource. There is also no public evidence yet of systems being encrypted, flights being affected or aircraft being placed at risk.

If the files are authentic, the employee information is probably the most immediate concern. Names, roles, employee IDs and training histories could support convincing spear-phishing attempts disguised as recurrent-training notices, roster changes, HR requests or document updates. Records from 2009–2020 may be old, but employment histories and identifiers can remain useful to criminals.

The claimed Boeing source code and proprietary manuals would present intellectual-property and potentially software-security concerns. However, possession of training material or engineering code does not provide control over an aircraft. For now, this should be described as a credible but unverified data-theft/extortion claim. A leak-site countdown is pressure, not proof; validation would require authentic samples, a Flydubai or regulator notification, or findings from the incident investigation.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top