CSIDB logo
Incident

Korean Air

Incident posture

Attack window
Nov 2025
Location
South Korea
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 16:06

Linked entities

Victim
Korean Air
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Nov 2025
Resolved
Pending

Summary

Korean Air disclosed that a cyberattack on its former subsidiary and catering supplier exposed personal information of about thirty thousand current and former employees, including names and bank account numbers, while customer data remained unaffected. The breach stemmed from the exploitation of Oracle E‑Business Suite zero‑day vulnerabilities in a campaign linked to the Cl0p ransomware group, which posted the subsidiary’s data on its leak site and released roughly five hundred gigabytes of stolen files. The incident is part of a broader series of intrusions affecting multiple organizations across sectors, though a separate employee‑data leak reported by another South Korean carrier is not connected to this campaign.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Korean Air Catering & Duty‑Free (KC&D) notified Korean Air that information belonging to the airline’s employees had been compromised. Korean Air subsequently confirmed that hackers had stolen the personal data of roughly 30,000 current and former employees from KC&D, including names and bank account numbers. The airline emphasized that no customer data was exposed in the incident. KC&D, which was originally a division of Korean Air before being spun off and sold to a private equity firm in 2020, continues to provide catering and duty‑free services to Korean Air and many other airlines worldwide.

The disclosed incident is described as likely related to the broader Oracle E‑Business Suite (EBS) campaign in which attackers exploited zero‑day vulnerabilities to infiltrate data stored by more than 100 organizations. Security analysts have linked the campaign to a cluster of the FIN11 threat group, while the Cl0p ransomware group has publicly claimed responsibility for the attacks. Cl0p added KC&D to its Tor‑based leak site on November 21 and subsequently released nearly 500 GB of archives allegedly containing files stolen from the company. The same Oracle EBS wave also victimized other aviation entities, notably American Airlines’ subsidiary Envoy Air, which was among the first confirmed victims. In contrast, a separate breach reported by Asiana Airlines affecting about 10,000 employees shows no indication of being connected to the Oracle EBS effort.

The breach at KC&D resulted in the exposure of names and bank account numbers for approximately 30,000 Korean Air current and former employees. Korean Air’s public statement confirmed the incident and emphasized that customer data remained unaffected. The airline did not disclose further technical details regarding containment or remediation efforts. The incident shows that a compromise at KC&D led to the exposure of Korean Air employee data.

Sources

Sources available to members: 1 source.

CSIDB