Menu
Browse

Cyber Incident Victim: Air Mauritius

Date:

Feb 2022

Location:

Mauritius

Summary

Air Mauritius experienced a cyberattack targeting its IT infrastructure, disrupting operations for nearly 24 hours. The incident forced staff to revert to manual processes for critical functions including ticket verification, flight load management, and crew scheduling after online systems became inaccessible. Official websites were also impacted, requiring the use of alternative networks and a full server reboot. Normal operations resumed the following day after systems were restored.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On February 14, 2022, Air Mauritius experienced a cyberattack that disrupted its IT network for approximately 24 hours, beginning on Monday morning and lasting until midday Tuesday. The initial cyber threats emerged on the airline’s servers early Monday, prompting immediate operational challenges as critical systems became inaccessible, including the official Air Mauritius website. This forced staff to abandon digital processes and revert entirely to manual operations across multiple departments. Primary impacts centered on ticketing verification, flight load management, and crew scheduling systems, which required handwritten documentation and physical record-keeping. The prolonged outage necessitated the use of alternative networks to maintain partial functionality while technicians addressed the breach. Unconfirmed reports indicated that Air Mauritius executed a full shutdown and restart of affected servers to contain the incident.

Cyber Incident Image

The transition to manual operations significantly slowed administrative workflows, with employees comparing the experience to reverting to pre-digital-era practices from 1968. Ground staff handled passenger check-ins and baggage processing without automated systems, while flight crews relied on printed schedules disseminated physically. Despite these measures, the airline sustained operational delays and reduced efficiency throughout the disruption period. Recovery efforts progressed gradually, with systems returning to normal functionality by Tuesday afternoon. No data theft or financial demands were mentioned in initial reports, with the focus remaining on restoring core operational capabilities. The incident concluded without disclosed details regarding attack vectors or perpetrator identification.

Sources
Sources available to members
1 source