Boeing confirms cyberattack on its parts and distribution business
- Organization
- Boeing
- Exploit
- Ransomware
- Industry
- Aerospace
Boeing confirmed in early November 2023 that a cyber incident had affected elements of its parts and distribution business, the unit that supplies spares and logistics services to airline and defense customers. The company said the incident did not affect flight safety.
The LockBit ransomware group had named Boeing on its leak site on October 27, claiming to have exfiltrated a large volume of sensitive data and threatening to publish it unless the company made contact within days. The Register reported that the gang also claimed to have used a zero-day exploit to gain access, an assertion Boeing did not address.
Boeing said it was investigating, had engaged a third-party cybersecurity firm and was coordinating with law enforcement and regulatory authorities, and that it was notifying customers and suppliers. Its parts and distribution website was offline during this period, which the company attributed to technical issues. Boeing did not issue a formal press release or a securities filing about the incident.
LockBit briefly removed Boeing from its victim list, a step that often signals negotiation or payment, then restored the listing and published roughly 43 gigabytes of material it said came from the company. Boeing did not pay. CyberScoop later reported that the gang had demanded 200 million dollars, among the largest publicly known ransom demands on record.