CSIDB logo
Incident

Aeroflot

Incident posture

Attack window
Jul 2025
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:24

Linked entities

Victim
Aeroflot
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Russian airline Aeroflot cancelled more than 50 round-trip flights and suffered widespread disruption to its operations after two pro-Ukraine hacking groups, Silent Crow and Belarusian Cyberpartisans, claimed a coordinated cyberattack that they said was the result of a year-long infiltration. The hackers alleged they destroyed 7,000 servers, gained control over employee devices including those of senior managers, and threatened to release personal data of past passengers along with intercepted staff communications, publishing screenshots of internal file directories as evidence. The Kremlin described the situation as worrying, Russian prosecutors opened a criminal investigation, and the company's shares dropped while departure boards at Moscow's Sheremetyevo Airport showed dozens of additional delays, leaving passengers stranded with limited access to the airline's website, app, and call center.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

3 techniques

Description

On the morning of Monday, July 28, 2025, Russia's national flag carrier, Aeroflot, was forced to cancel more than fifty round-trip flights after a coordinated cyberattack penetrated the airline's core information systems. The Kremlin publicly acknowledged that the situation was "worrying," and senior Russian lawmakers described the breach as a wake-up call for the country's digital defenses. Russian prosecutors quickly confirmed that the disruption at Aeroflot was caused by a hack and opened a formal criminal case. The incident produced widespread travel chaos across the Russian Federation at a time when many citizens were beginning their summer holidays, with departure boards at Moscow's Sheremetyevo Airport turning red as flights were cancelled or delayed by hours. By 1533 GMT, Aeroflot's share price had fallen by 3.9 percent, underperforming the broader Russian market, which was down by 1.3 percent on the same day. The combined operational and financial impact made the event one of the most consequential cyber incidents affecting a Russian civilian enterprise since the start of the war in Ukraine.

Responsibility for the attack was publicly claimed by two pro-Ukraine hacktivist groups operating in cooperation: a group identifying itself as Silent Crow and the Belarusian Cyberpartisans, a self-styled hacktivist organization opposed to President Alexander Lukashenko that seeks the liberation of Belarus from dictatorship. In a joint statement attributed to Silent Crow and released publicly, the groups said the operation had been a year-long effort which had deeply penetrated Aeroflot's internal network. According to their claims, the attackers destroyed approximately 7,000 servers within Aeroflot's infrastructure and gained persistent control over the personal computers of employees, including those belonging to senior managers. The groups posted screenshots purporting to show internal file directories from inside Aeroflot's network as evidence of their access. Silent Crow further threatened that it would soon begin releasing "the personal data of all Russians who have ever flown Aeroflot," alongside intercepted conversations and emails belonging to Aeroflot staff. The statement ended with the slogans "Glory to Ukraine! Long live Belarus!" The Cyberpartisans confirmed their participation on their own website, stating, "We are helping Ukrainians in their fight with the occupier, carrying out a cyber strike on Aeroflot and paralysing the largest airline in Russia." Ukrainian officials made no immediate comment on the incident.

The operational fallout inside Aeroflot was immediate and severe. The airline announced that it had cancelled 54 round-trip flights out of a total of 260 scheduled for the day, leaving 206 flights still planned to operate once systems could be stabilized. An online departure board for Sheremetyevo International Airport showed dozens of additional flights delayed by hours as the airline's internal scheduling, ticketing, and crew assignment systems failed. Aeroflot issued a statement saying, "Specialists are currently working to minimise the impact on the flight schedule and to restore normal service operations," but declined to provide an estimate for when full service would resume. Beyond the IT systems themselves, ancillary passenger-facing channels also collapsed: passengers noted that the call centre was unreachable, the corporate website was unavailable, and the Aeroflot mobile application could not be accessed. With normal customer service channels offline, affected travelers were left to queue at airports and vent frustration on the Russian social network VK. One stranded passenger, Malena Ashi, posted that she had been sitting at Volgograd airport since 03:30, with her flight rescheduled three times and pushed from its original 05:00 departure to approximately 14:50. Another passenger, Yulia Pakhota, complained, "The call centre is unavailable, the website is unavailable, the app is unavailable. How can I return a ticket or exchange it for the next flight, as Aeroflot suggests?" In response, Aeroflot stated that affected passengers would be eligible for a refund or rebooking once systems were restored, and that the airline was attempting to secure seats on other carriers where capacity allowed.

The political reaction inside Russia was swift. Kremlin spokesman Dmitry Peskov told reporters, "The information that we are reading in the public domain is quite alarming. The hacker threat is a threat that remains for all large companies providing services to the population." Senior State Duma member Anton Gorelkin framed the attack as part of a broader hybrid war being waged against Russia, declaring, "We must not forget that the war against our country is being waged on all fronts, including the digital one. And I do not rule out that the 'hacktivists' who claimed responsibility for the incident are in the service of unfriendly states." Another lawmaker, Anton Nemkin, called on investigators to identify not only the attackers themselves but also those inside Aeroflot and the broader Russian digital infrastructure "who allowed systemic failures in protection." The dual messaging from politicians — acknowledging the severity of the breach while suggesting possible state involvement — signaled that the Russian government viewed the Aeroflot incident as both a criminal matter and a national security concern.

Silent Crow's claim of responsibility was not its first high-profile action. Earlier in 2025, the group publicly claimed responsibility for cyber operations against a Russian real estate database, a Russian state telecommunications company, a large insurance firm, the Moscow government's IT department, and the Russian office of the South Korean automaker KIA, several of which resulted in significant data leaks. The Aeroflot operation therefore marked an escalation in both the scale of disruption and the public profile of the targets chosen by the group, moving from data theft and website defacement to the crippling of operational technology in a critical civilian service. Former Aeroflot pilot and aviation analyst Andrei Litvinov described the incident in stark terms to Reuters: "This is a serious disaster. Okay, flight delays – you can survive that. But these are losses, huge losses for a state-owned company." Litvinov further warned that if the attackers followed through on their threat to publish internal correspondence and corporate data, the consequences would extend well beyond the immediate flight disruptions. He noted that Russian travelers had already grown accustomed to disruption caused by temporary airport closures during Ukrainian drone strikes, but that this incident represented a qualitatively different attack vector, striking from within the company's own systems.

The wider context for the breach included the substantial Western sanctions regime imposed on Russia since the February 2022 invasion of Ukraine, which has drastically limited Aeroflot's international route network and available aircraft and insurance options. Despite these restrictions, Aeroflot remained among the top twenty airlines in the world by passenger numbers, carrying approximately 55.3 million passengers in the previous year according to the airline's own published statistics. That scale made the operational disruption visible not only inside Russia but also to international observers tracking the resilience of critical infrastructure under sustained cyber pressure. As of the close of reporting on July 28, Aeroflot had not publicly disclosed the technical vector used by the attackers, the exact timeline for restoring its systems, or whether any customer or employee data had already been exfiltrated beyond the claims made by Silent Crow and the Belarusian Cyberpartisans. Russian prosecutors, Aeroflot's internal IT staff, and outside specialists were continuing to work on restoring normal operations and assessing the full scope of the intrusion.

Sources

Sources available to members: 1 source.

CSIDB