CSIDB logo
Incident

Kenya Airways

Incident posture

Attack window
Dec 2023
Location
Kenya
Status
Historical
CIA posture
Available to members
Updated
2026-01-04 23:39

Linked entities

Victim
Kenya Airways
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Kenya Airways experienced a significant ransomware attack resulting in the unauthorized disclosure of confidential company data by the Ransomexx hacking group. The compromised information included passenger records, investigative materials, death and accident reports, passport applications, and strategic carrier plans, exposing sensitive operational and customer details.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Kenya Airways Ltd., the flag carrier of Kenya, experienced a significant ransomware attack on December 30, 2023. The incident resulted in unauthorized access to confidential company data, which was subsequently leaked on the internet by the threat actors. The hacking group Ransomexx claimed responsibility for the breach and publicly released samples of stolen information to demonstrate the success of their operation. This attack compromised sensitive airline records containing personal and operational details spanning multiple categories of the carrier's activities. The breach exposed internal documents that extended beyond typical passenger information to include specialized investigative files maintained by the organization.

The leaked data encompassed historical passenger records, death certificates, accident investigation reports, passport application documents, and strategic plans related to airline operations. The exposure of death records and accident reports indicated the attackers accessed highly sensitive documentation typically protected for legal and privacy reasons. Passport application details within the breach raised concerns about identity theft risks for affected individuals. The theft of strategic carrier plans suggested potential competitive disadvantages for Kenya Airways in future aviation markets. While the full scope of compromised systems remained unspecified, the diversity of leaked records demonstrated wide-ranging access across multiple data repositories within the airline's infrastructure.

Sources

Sources available to members: 1 source.

CSIDB