Multinational airline AirAsia is currently dealing with the aftermath of a ransomware attack that has resulted in the theft of personal data for more than five million people.

AirAsia is a multinational low-cost airline headquartered near Kuala Lumpar in Malaysia. 

It is the largest airline in Malaysia, and operates scheduled domestic and international flights to more than 165 destinations across 25 countries.

The Ransomware Group

The criminals behind the ransomware attack are China-based gang “Daixin Team”, a group engaging in increasing activity over the last few months. The gang is dangerous enough to warrant an alert from the FBI and CISA.

The group has been active since June 2022, although previously has only targeted health care and public health facilities. The “Daixin Team” is notable for entering organisations networks through unpatched VPN vulnerabilities, a cyber security weakness that has become increasingly common since the COVID-19 pandemic prompted an increase in remote working, which prompted an increased need for Virtual Private Networks (VPNs).

The ransomware attack on AirAsia took place over two days, on the 11th and 12th of November. The cybercriminals leaked a portion of the stolen data a week after the incident to their dark web page, which included personal information from both AirAsia’s employees and their passengers’ booking information. The cybercriminals claim that they have captured “all employees” personal data, and an unspecified quantity of passenger data.

The “Daixen Team” has also stated that they would no longer target AirAsia with ransomware attacks, due to the company’s “chaotic organization”, and poor cybersecurity. The group have also claimed to be sympathetic, refusing to affect any systems that could cause loss of life, such as their air traffic control and radar systems, despite having access.

Increasing Ransomware Incidents

Ransomware attacks have not only become more frequent and expensive to recover from, but have also become substantially more dangerous. Cybercriminals have started to demonstrate that they are prepared to cause real-world damage, with the first death directly caused by a cyber-attack occurring when a ransomware attack crippled a hospital in Dusseldorf, delaying a critical patient transfer, and causing the patient’s death.

While Daixin Team’s claim that they had access to air traffic control and other sensitive airline software is alarming, cyber security researchers are doubtful whether their claim is accurate.

Such access would require infiltrating the individual’s airport systems rather than an airline’s internal network or booking system. Previous attacks on airlines have shown that access to critical systems is not common or easy to achieve. The closest cybercriminals have ever come to such access was an attack on Bristol Airport in 2018 that caused flight outages for two days, but did not impact actual aircraft operations. FedEx’s air shipment service has also been hit by ransomware attacks twice in the past, but still flight operations have not been impacted.

Security researcher Nick Tausek has commented on this attack, stating that ransomware is now a risk that all sizes of organisations need to consider:

Since June of 2022, the Daixin Group has attacked several healthcare organisations. These attacks resulted in the exposure of personally identifiable information (PII) on the dark web and represented a significant threat to patient and employee safety. Now, the Daixin Group seems to be shifting towards new targets – global infrastructure. Unfortunately, AirAsia will most likely face large financial burdens and a crisis of confidence from its consumer base due to this attack“. 
To mitigate the chances of similar attacks in the future, it is imperative that organisations adopt low-code security automation to help detect and respond to threats in real-time by allowing complete visibility into IT environments. Endpoint security tools that integrate low-code security automation give organisations a cohesive protection strategy“.
 
TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
We are currently offering a free service that will help to identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the current best methods of identifying phishing emails: