ICAO confirms recruitment database breach affecting nearly 12,000 people

Organization
International Civil Aviation Organization
Exploit
Hacking
Industry
Government

The International Civil Aviation Organization, the United Nations body that sets global standards for civil aviation, confirmed in January 2025 that recruitment records held in its systems had been stolen and published.

The incident surfaced on January 6, 2025, when an actor using the name Natohub advertised roughly 42,000 ICAO job application records on a hacking forum and posted sample recruitment forms as proof. ICAO acknowledged the claim the following day and said it was investigating.

In an update on January 10 the agency said that after reviewing the data it could confirm 11,929 individuals were affected. The applications spanned April 2016 to July 2024 and the exposed fields included names, email addresses, dates of birth and employment history. ICAO said no financial information, passwords, passport details or applicant uploaded documents were involved, and that the breach was confined to the recruitment database and did not extend to systems supporting aviation safety or security.

The organization said it had strengthened its security measures, opened a dedicated mailbox for enquiries at [email protected] and started contacting the people whose records were affected. Reporting on the forum listing noted the dataset advertised contained tens of thousands of unique email addresses, including government domains, a larger count than the individuals ICAO ultimately confirmed.

Sources