Rhysida ransomware attack disrupted Seattle-Tacoma International Airport systems
- Organization
- Port of Seattle (Seattle-Tacoma International Airport)
- Exploit
- Ransomware
- Industry
- Aviation
The Port of Seattle, which operates Seattle-Tacoma International Airport, detected unauthorized activity on its network on August 24, 2024 and isolated critical systems in response. The disruption spread across technology passengers rely on, including baggage handling, check-in kiosks, ticketing, Wi-Fi, passenger information displays, reserved parking, the flySEA mobile app and the Port's website, email and phone systems.
No mass flight cancellations were reported in the first days, but the outage forced manual workarounds during one of the busiest travel stretches of the year. Gate agents handwrote boarding passes at common use gates and airlines sorted bags by hand, with one carrier working through more than 7,000 pieces of luggage. Bags reached some travelers well after they had arrived.
The Port said it was investigating with outside experts and working with federal partners including the Transportation Security Administration and Customs and Border Protection. Systems were restored over the following two weeks, and the Port reported near normal operations by September 6, 2024.
On September 13, 2024 the Port publicly attributed the incident to the Rhysida ransomware group, said portions of its systems had been encrypted, and stated it had no intent of paying. Rhysida listed the Port on its leak site with a demand of 100 bitcoin. The Port subsequently determined that personal information held in legacy systems for employees, contractors and parking customers had been taken, including names, dates of birth, Social Security numbers, government identification numbers and some medical information, and mailed notification letters in April 2025.