Menu
Browse

Cyber Incident Victim: Accelya

Date:

Aug 2022

Location:

India

Summary

A major airline technology provider serving over 250 carriers globally experienced a ransomware attack by the AlphV/Black Cat group, which claimed to steal emails, worker contracts, and other data before publishing it on their leak site. The company contained the malware to a limited portion of its environment, preventing lateral movement to customer systems, and engaged forensic experts to investigate the breach. While reviewing the leaked data to identify potentially exposed customer information, the incident highlighted the airline sector's vulnerability to ransomware threats, with AlphV/Black Cat—linked to earlier groups like BlackMatter and DarkSide—remaining highly active across multiple industries.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around August 11, 2022, the AlphV/Black Cat ransomware group executed an attack against Accelya, a global technology provider serving over 250 airlines across nine countries, including major carriers such as Delta, British Airways, and United. The attackers exfiltrated company data—including emails, worker contracts, and unspecified additional information—and published it on their leak site on August 11. Accelya confirmed the incident on August 16 after two cybersecurity firms it engaged discovered the data dump. Forensic investigators determined the ransomware was confined to a limited segment of Accelya’s infrastructure, with no evidence of lateral movement into customer environments. The company stated it successfully quarantined the malware before broader propagation occurred.

Cyber Incident Image

Accelya initiated a review of the leaked data to identify compromised customer information and committed to notifying affected parties. The incident occurred amid heightened targeting of the aviation sector in 2022, including May ransomware attacks against India’s SpiceJet and a Canadian fighter jet supplier. AlphV/Black Cat, identified by the FBI as responsible for at least 60 ransomware incidents by March 2022, has been linked to prior groups BlackMatter and DarkSide—the latter notorious for the Colonial Pipeline attack. The group concurrently targeted entities including the city government of Alexandria, Louisiana, energy companies in Luxembourg, and Bandai Namco in July 2022. Accelya’s operational platforms for airline retailing, cargo, and analytics remained functional during the containment effort, with no reported service disruptions to clients.

Sources
Sources available to members
1 source