Korean Air
Incident posture
Linked entities
- Victim
- Korean Air
- Threat actors
- 2 actors
- Sources
- 1 source
Timeline
Summary
Korean Air disclosed that a cyberattack on its former subsidiary and catering supplier exposed personal information of about thirty thousand current and former employees, including names and bank account numbers, while customer data remained unaffected. The breach stemmed from the exploitation of Oracle E‑Business Suite zero‑day vulnerabilities in a campaign linked to the Cl0p ransomware group, which posted the subsidiary’s data on its leak site and released roughly five hundred gigabytes of stolen files. The incident is part of a broader series of intrusions affecting multiple organizations across sectors, though a separate employee‑data leak reported by another South Korean carrier is not connected to this campaign.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Korean Air Catering & Duty‑Free (KC&D) notified Korean Air that information belonging to the airline’s employees had been compromised. Korean Air subsequently confirmed that hackers had stolen the personal data of roughly 30,000 current and former employees from KC&D, including names and bank account numbers. The airline emphasized that no customer data was exposed in the incident. KC&D, which was originally a division of Korean Air before being spun off and sold to a private equity firm in 2020, continues to provide catering and duty‑free services to Korean Air and many other airlines worldwide.
The disclosed incident is described as likely related to the broader Oracle E‑Business Suite (EBS) campaign in which attackers exploited zero‑day vulnerabilities to infiltrate data stored by more than 100 organizations. Security analysts have linked the campaign to a cluster of the FIN11 threat group, while the Cl0p ransomware group has publicly claimed responsibility for the attacks. Cl0p added KC&D to its Tor‑based leak site on November 21 and subsequently released nearly 500 GB of archives allegedly containing files stolen from the company. The same Oracle EBS wave also victimized other aviation entities, notably American Airlines’ subsidiary Envoy Air, which was among the first confirmed victims. In contrast, a separate breach reported by Asiana Airlines affecting about 10,000 employees shows no indication of being connected to the Oracle EBS effort.
The breach at KC&D resulted in the exposure of names and bank account numbers for approximately 30,000 Korean Air current and former employees. Korean Air’s public statement confirmed the incident and emphasized that customer data remained unaffected. The airline did not disclose further technical details regarding containment or remediation efforts. The incident shows that a compromise at KC&D led to the exposure of Korean Air employee data.
Sources
Sources available to members: 1 source.