Korean Air Catering & Duty-Free
Incident posture
Linked entities
- Victim
- Korean Air Catering & Duty-Free
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Korean Air disclosed that a cyberattack on its former subsidiary and current catering supplier resulted in the theft of roughly 30 000 employee records containing names and bank account numbers while customer data remained unaffected. The intrusion is tied to a widespread Oracle E‑Business Suite zero‑day exploit campaign linked to the FIN11 threat group, with the Cl0p ransomware group claiming responsibility and publishing about 500 GB of stolen data on its leak site. Other organizations, including American Airlines subsidiary Envoy Air, were also victimized in the same campaign, whereas a separate incident affecting Asiana Airlines appears unrelated.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Korean Air Catering & Duty-Free (KC&D) was originally a division of Korean Air. It was spun off and sold to a private equity firm in 2020. KC&D continues to provide catering services to Korean Air and many other airlines worldwide. In late 2025, KC&D was targeted in a cyberattack that exploited zero‑day vulnerabilities in Oracle E‑Business Suite (EBS). This attack was part of a broader campaign affecting over 100 organizations and is linked to the Cl0p ransomware group, which publicly claimed responsibility, added KC&D to its Tor‑based leak site on November 21, and subsequently released nearly 500 GB of archives allegedly stolen from the company.
Korean Air was informed by KC&D that employee data belonging to the airline had been compromised. The airline confirmed that roughly 30,000 current and former employees’ records were stolen. The stolen information included names and bank account numbers. Korean Air stated that customer data was not exposed in the incident. The breach is considered likely related to the Oracle EBS campaign, which also affected other aviation entities such as American Airlines’ subsidiary Envoy Air.
Around the same time, Asiana Airlines reported a separate incident affecting about 10,000 employees, with no indication of connection to the Oracle EBS campaign. In response to the KC&D breach, Korean Air publicly disclosed the incident, confirmed the theft of employee information, and emphasized that no customer data had been exposed. The airline’s statement served as the primary communicated action regarding the incident.
Sources
Sources available to members: 1 source.