CSIDB logo
Incident

Malaysia Airlines

Incident posture

Attack window
Mar 2014
Location
Malaysia
Status
Historical
CIA posture
Available to members
Updated
2026-02-01 18:17

Linked entities

Victim
Malaysia Airlines
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Computers belonging to high-ranking officials involved in the MH370 investigation were compromised by malware designed to steal classified information, with exfiltrated data transmitted to a server in China before domestic cybersecurity authorities intervened to block transmissions and isolate infected systems. The breach targeted sensitive details related to the ongoing probe, requiring mitigation efforts by a national cybersecurity agency to halt unauthorized data transfers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In August 2014, computers belonging to high-ranking officials within Malaysian agencies involved in the investigation of Malaysia Airlines Flight MH370 were compromised by hackers. The attackers deployed malware that exfiltrated classified information related to the ongoing probe into the aircraft's disappearance. Stolen data was transmitted to a computer located in China, indicating a targeted effort to acquire sensitive investigative materials. CyberSecurity Malaysia, an agency under the Ministry of Science, Technology and Innovation, detected the unauthorized data transmissions and intervened to disrupt the operation. The agency blocked further transfers of information and initiated containment measures by shutting down the infected machines to prevent additional data loss. The incident directly impacted critical systems handling the MH370 investigation, though the specific volume or nature of stolen data was not publicly quantified.

The breach compromised systems operated by officials central to the multinational search effort for MH370, which vanished in March 2014 with 239 people aboard. CyberSecurity Malaysia's response focused on terminating active data exfiltration and isolating affected devices to limit operational disruption. No evidence suggested the malware spread beyond systems associated with the investigation or persisted after containment. The incident underscored vulnerabilities in infrastructure managing highly sensitive aviation disaster inquiries but did not result in publicly disclosed changes to the MH370 investigation's trajectory. Authorities did not attribute the attack to specific actors or elaborate on whether stolen data was recovered.

Sources

Sources available to members: 1 source.

CSIDB