Multinational airline AirAsia is currently dealing with the aftermath of a ransomware attack that has resulted in the theft of personal data for more than five million people.
AirAsia is a multinational low-cost airline headquartered near Kuala Lumpar in Malaysia.
It is the largest airline in Malaysia, and operates scheduled domestic and international flights to more than 165 destinations across 25 countries.
The Ransomware Group
The criminals behind the ransomware attack are China-based gang “Daixin Team”, a group engaging in increasing activity over the last few months. The gang is dangerous enough to warrant an alert from the FBI and CISA.
The group has been active since June 2022, although previously has only targeted health care and public health facilities. The “Daixin Team” is notable for entering organisations networks through unpatched VPN vulnerabilities, a cyber security weakness that has become increasingly common since the COVID-19 pandemic prompted an increase in remote working, which prompted an increased need for Virtual Private Networks (VPNs).
The ransomware attack on AirAsia took place over two days, on the 11th and 12th of November. The cybercriminals leaked a portion of the stolen data a week after the incident to their dark web page, which included personal information from both AirAsia’s employees and their passengers’ booking information. The cybercriminals claim that they have captured “all employees” personal data, and an unspecified quantity of passenger data.
The “Daixen Team” has also stated that they would no longer target AirAsia with ransomware attacks, due to the company’s “chaotic organization”, and poor cybersecurity. The group have also claimed to be sympathetic, refusing to affect any systems that could cause loss of life, such as their air traffic control and radar systems, despite having access.
Increasing Ransomware Incidents
Ransomware attacks have not only become more frequent and expensive to recover from, but have also become substantially more dangerous. Cybercriminals have started to demonstrate that they are prepared to cause real-world damage, with the first death directly caused by a cyber-attack occurring when a ransomware attack crippled a hospital in Dusseldorf, delaying a critical patient transfer, and causing the patient’s death.
While Daixin Team’s claim that they had access to air traffic control and other sensitive airline software is alarming, cyber security researchers are doubtful whether their claim is accurate.
Such access would require infiltrating the individual’s airport systems rather than an airline’s internal network or booking system. Previous attacks on airlines have shown that access to critical systems is not common or easy to achieve. The closest cybercriminals have ever come to such access was an attack on Bristol Airport in 2018 that caused flight outages for two days, but did not impact actual aircraft operations. FedEx’s air shipment service has also been hit by ransomware attacks twice in the past, but still flight operations have not been impacted.
Security researcher Nick Tausek has commented on this attack, stating that ransomware is now a risk that all sizes of organisations need to consider:







