CSIDB logo
Incident

The Boeing Company

Incident posture

Attack window
May 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-31 02:05

Linked entities

Victim
The Boeing Company
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Boeing production facility in South Carolina was disrupted by the WannaCry ransomware, which targeted systems via a Windows vulnerability, causing concerns over halted assembly tools and potential spread to equipment used for functional airplane tests. The attack, later attributed to North Korea by U.S. officials, encrypted machines and demanded cryptocurrency payments for restoration, mirroring widespread global impacts that previously crippled critical infrastructure like hospitals. While patches were issued to mitigate propagation, the incident highlighted risks to industrial operations from rapidly spreading malware.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 12, 2017, Boeing's commercial airplane production facility in Charleston, South Carolina, experienced a WannaCry ransomware infection that disrupted manufacturing operations. The attack prompted chief engineer Mike VanderWel to issue a company-wide memo declaring an "all hands on deck" emergency response. VanderWel's communication, obtained by the Seattle Times, indicated the malware was "metastasizing rapidly" from the North Charleston location with immediate concerns about critical 777 jet production systems. Specifically, automated spar assembly tools supporting 777 manufacturing were reported as potentially compromised. Boeing officials expressed additional concerns that the ransomware could propagate to equipment used for functional testing of aircraft, creating pathways for the infection to potentially spread to operational airplane software systems. The incident occurred during the global WannaCry outbreak that initially paralyzed UK healthcare systems and subsequently impacted over 150 countries.

The WannaCry ransomware exploited a critical vulnerability in Microsoft Windows operating systems, encrypting files and demanding cryptocurrency payments for decryption. While Microsoft had released security patches prior to the Boeing incident, unpatched systems remained vulnerable to infection. The malware's rapid propagation through Boeing's production network suggested possible lateral movement across connected industrial systems. The Trump administration formally attributed WannaCry to North Korea's cyber operations unit in December 2017, though this attribution occurred seven months after the Boeing incident. Boeing's containment efforts focused on preventing the ransomware from compromising flight-critical systems, though the Seattle Times report did not specify whether production delays or financial losses resulted. The event highlighted vulnerabilities in industrial control systems within aerospace manufacturing environments despite available security patches.

Sources

Sources available to members: 1 source.

CSIDB