Airbus supplier data leaked after credentials stolen from airline employee
- Organization
- Airbus
- Exploit
- Credential Compromise
- Industry
- Aerospace
Airbus confirmed in September 2023 that it was investigating a data leak after a user of the BreachForums cybercrime site posted information said to relate to about 3,200 of the aerospace manufacturer's suppliers. The Record reported that the leak came to light on 12 September 2023, a day after it was published.
The poster used the handle USDoD and had previously claimed the December 2022 breach of the FBI's InfraGard portal. The records were described as vendor contact details including names, addresses, telephone numbers and email addresses. Companies referenced in the material included Rockwell Collins and Thales.
USDoD said access came through the account of an employee at a Turkish airline that had third-party access to an Airbus web portal. Threat intelligence firm Hudson Rock, which recovered logs from the compromised machine, reported that the employee had been infected with the RedLine information stealer after downloading pirated software. Krebs on Security reported that the malware harvested passwords, authentication cookies and tokens capable of defeating multi-factor authentication.
An Airbus spokesperson, Philippe Gmerek, said immediate remedial and follow-up measures were taken by the company's security teams to prevent its systems from being compromised. Airbus did not confirm the size of the data set. No ransom demand accompanied the posting, and the actor said at the time that he had joined a group operating under the Ransomed name.