CSIDB logo
Incident

SITA

Incident posture

Attack window
Mar 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
SITA
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major cyberattack targeted SITA, a critical IT and communications provider serving approximately 90% of global airlines, compromising passenger data through a breach of its U.S.-based servers. The highly sophisticated incident affected the Passenger Service System infrastructure located in Atlanta, leading to unauthorized access to frequent-flyer information across multiple airline carriers. The breach impacted systems responsible for processing passenger data, underscoring supply-chain vulnerabilities within the aviation sector.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On March 5, 2021, SITA, a critical communications and IT provider serving approximately 90% of global airlines, disclosed a significant cybersecurity breach impacting its U.S.-based infrastructure. The company confirmed unauthorized access to servers located in Atlanta, Georgia, which hosted its Passenger Service System (SITA PSS). This system managed airline passenger data processing operations for numerous carriers worldwide. SITA characterized the intrusion as a "highly sophisticated attack" targeting its U.S. operations segment, though specific technical details about the attack vector or duration of unauthorized access remained undisclosed. The compromised servers belonged to SITA's Passenger Service System division, part of a broader corporate structure headquartered within the European Union.

The breach directly affected sensitive passenger information stored on the Atlanta-based servers, specifically compromising frequent-flyer program data across multiple airline customers. As a central provider of passenger data systems, the incident created cascading impacts across SITA's extensive client network of international airlines. No specific airlines were named in initial disclosures, but the widespread nature of SITA's operations suggested broad sectoral exposure. The company's public statement, delivered through spokesperson Edna Ayme-Yahil, confirmed the geographic location of breached assets but did not disclose quantitative details regarding affected passengers or airlines. SITA initiated incident response protocols focused on securing compromised systems, though containment measures and forensic investigation timelines were not publicly detailed. The incident highlighted supply chain vulnerabilities in aviation IT infrastructure through the compromise of a single vendor supporting nearly all major airlines globally.

Sources

Sources available to members: 1 source.

CSIDB