Menu
Browse

Cyber Incident Victim: Albany International Airport

Date:

Dec 2019

Location:

United States of America

Summary

Albany International Airport experienced a ransomware attack by the Sodinokibi group targeting administrative servers, which encrypted archived data and documents without disrupting flight operations or compromising passenger or airline information. The airport paid a ransom under six figures, partially reimbursed by their insurer after a deductible charged to third-party provider LogicalNet, whose services were terminated following the incident. Administrative functions were restored within hours through IT efforts, with assistance from the FBI, New York State Cyber Command, and cybersecurity firm ABS Solutions.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around December 25, 2019, Albany International Airport's administrative servers were compromised in a cyberattack involving Sodinokibi ransomware. The attack encrypted administrative documents and archived data but did not impact airport operations, airline systems, or Transportation Security Administration (TSA) servers. Airport officials confirmed no unauthorized access to passenger financial or personal information occurred. The Albany County Airport Authority immediately notified the FBI and New York State Cyber Command upon discovering the incident and engaged cybersecurity firm ABS Solutions to assist with the investigation. Due to the unavailability of backups, the airport paid a ransom demand described as "under six figures" to regain access to encrypted systems. Airport CEO Philip Calderone stated administrative functions were restored within hours through rapid IT department intervention, ensuring normal operations continued during the busy holiday travel period.

Cyber Incident Image

The airport's insurer reimbursed most of the ransom payment, with the airport responsible for a $25,000 deductible billed to LogicalNet, their former IT provider. Calderone announced the termination of the airport's relationship with LogicalNet following the attack. No evidence suggested data exfiltration beyond the encryption of administrative files. The incident occurred amid a broader wave of Sodinokibi ransomware activity, including contemporaneous attacks on Travelex foreign exchange services and U.S. data center provider CyrusOne. While Travelex faced threats of stolen data publication, Albany International Airport reported no comparable data exposure. Calderone publicly acknowledged assistance from law enforcement and cybersecurity partners in resolving the incident, emphasizing the containment of operational disruptions despite the administrative system compromise.

Sources
Sources available to members
1 source