Menu
Browse

Cyber Incident Victim: Malaysia Airlines

Date:

Mar 2014

Location:

Malaysia

Summary

Computers belonging to high-ranking officials involved in the MH370 investigation were compromised by malware designed to steal classified information, with exfiltrated data transmitted to a server in China before domestic cybersecurity authorities intervened to block transmissions and isolate infected systems. The breach targeted sensitive details related to the ongoing probe, requiring mitigation efforts by a national cybersecurity agency to halt unauthorized data transfers.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In August 2014, computers belonging to high-ranking officials within Malaysian agencies involved in the investigation of Malaysia Airlines Flight MH370 were compromised by hackers. The attackers deployed malware that exfiltrated classified information related to the ongoing probe into the aircraft's disappearance. Stolen data was transmitted to a computer located in China, indicating a targeted effort to acquire sensitive investigative materials. CyberSecurity Malaysia, an agency under the Ministry of Science, Technology and Innovation, detected the unauthorized data transmissions and intervened to disrupt the operation. The agency blocked further transfers of information and initiated containment measures by shutting down the infected machines to prevent additional data loss. The incident directly impacted critical systems handling the MH370 investigation, though the specific volume or nature of stolen data was not publicly quantified.

Cyber Incident Image

The breach compromised systems operated by officials central to the multinational search effort for MH370, which vanished in March 2014 with 239 people aboard. CyberSecurity Malaysia's response focused on terminating active data exfiltration and isolating affected devices to limit operational disruption. No evidence suggested the malware spread beyond systems associated with the investigation or persisted after containment. The incident underscored vulnerabilities in infrastructure managing highly sensitive aviation disaster inquiries but did not result in publicly disclosed changes to the MH370 investigation's trajectory. Authorities did not attribute the attack to specific actors or elaborate on whether stolen data was recovered.

Sources
Sources available to members
1 source