CSIDB logo
Incident

Korean Air Catering & Duty-Free

Incident posture

Attack window
Nov 2025
Location
South Korea
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 16:03

Linked entities

Victim
Korean Air Catering & Duty-Free
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Nov 2025
Resolved
Pending

Summary

Korean Air disclosed that a cyberattack on its former subsidiary and current catering supplier resulted in the theft of roughly 30 000 employee records containing names and bank account numbers while customer data remained unaffected. The intrusion is tied to a widespread Oracle E‑Business Suite zero‑day exploit campaign linked to the FIN11 threat group, with the Cl0p ransomware group claiming responsibility and publishing about 500 GB of stolen data on its leak site. Other organizations, including American Airlines subsidiary Envoy Air, were also victimized in the same campaign, whereas a separate incident affecting Asiana Airlines appears unrelated.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Korean Air Catering & Duty-Free (KC&D) was originally a division of Korean Air. It was spun off and sold to a private equity firm in 2020. KC&D continues to provide catering services to Korean Air and many other airlines worldwide. In late 2025, KC&D was targeted in a cyberattack that exploited zero‑day vulnerabilities in Oracle E‑Business Suite (EBS). This attack was part of a broader campaign affecting over 100 organizations and is linked to the Cl0p ransomware group, which publicly claimed responsibility, added KC&D to its Tor‑based leak site on November 21, and subsequently released nearly 500 GB of archives allegedly stolen from the company.

Korean Air was informed by KC&D that employee data belonging to the airline had been compromised. The airline confirmed that roughly 30,000 current and former employees’ records were stolen. The stolen information included names and bank account numbers. Korean Air stated that customer data was not exposed in the incident. The breach is considered likely related to the Oracle EBS campaign, which also affected other aviation entities such as American Airlines’ subsidiary Envoy Air.

Around the same time, Asiana Airlines reported a separate incident affecting about 10,000 employees, with no indication of connection to the Oracle EBS campaign. In response to the KC&D breach, Korean Air publicly disclosed the incident, confirmed the theft of employee information, and emphasized that no customer data had been exposed. The airline’s statement served as the primary communicated action regarding the incident.

Sources

Sources available to members: 1 source.

CSIDB