Cyber Incident Victim: Kenya Airways
Date:
Dec 2023
Location:
Kenya
Summary
Kenya Airways experienced a significant ransomware attack resulting in the unauthorized disclosure of confidential company data by the Ransomexx hacking group. The compromised information included passenger records, investigative materials, death and accident reports, passport applications, and strategic carrier plans, exposing sensitive operational and customer details.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Kenya Airways Ltd., the flag carrier of Kenya, experienced a significant ransomware attack on December 30, 2023. The incident resulted in unauthorized access to confidential company data, which was subsequently leaked on the internet by the threat actors. The hacking group Ransomexx claimed responsibility for the breach and publicly released samples of stolen information to demonstrate the success of their operation. This attack compromised sensitive airline records containing personal and operational details spanning multiple categories of the carrier's activities. The breach exposed internal documents that extended beyond typical passenger information to include specialized investigative files maintained by the organization.

The leaked data encompassed historical passenger records, death certificates, accident investigation reports, passport application documents, and strategic plans related to airline operations. The exposure of death records and accident reports indicated the attackers accessed highly sensitive documentation typically protected for legal and privacy reasons. Passport application details within the breach raised concerns about identity theft risks for affected individuals. The theft of strategic carrier plans suggested potential competitive disadvantages for Kenya Airways in future aviation markets. While the full scope of compromised systems remained unspecified, the diversity of leaked records demonstrated wide-ranging access across multiple data repositories within the airline's infrastructure.
