On Monday, Russian national carrier Aeroflot was forced to cancel over 40 flights following a major disruption in its information systems, which the airline described as a system failure.

Credit – Facebook
However, a hacker collective named Silent Crow, allegedly working in coordination with a Belarusian cyber activist group called Cyberpartisans BY, claimed responsibility for what they characterized as a coordinated and crippling cyberattack.
While Aeroflot did not disclose the specific cause or technical nature of the disruption, the hacking group Silent Crow released a statement — unverified by Reuters — claiming the attack had:
Been in planning and execution for over a year.
Resulted in the destruction of 7,000 servers.
Gained deep access to Aeroflot’s internal network, including control over the personal computers of employees, notably senior executives.
The attackers also threatened to leak personal data of every individual who has flown with Aeroflot, suggesting potential exposure of millions of passengers’ information, including Russian citizens and international travelers. If true, this could represent a severe breach of personal privacy and national aviation security.
The immediate impact was widespread flight cancellations, with Aeroflot listing over 40 affected routes, including domestic flights and services to Minsk (Belarus) and Yerevan (Armenia). The airline urged passengers departing from Moscow’s Sheremetyevo Airport to collect their checked-in baggage and leave the terminal, Reuters news report said on Monday.
Reports from the independent news outlet Baza described chaotic scenes at Sheremetyevo, with passengers stuck in queues and airport operations severely hampered. This underscores the dependence of modern airline infrastructure on digital systems and the cascading effects when they are compromised.
Silent Crow had earlier claimed responsibility for an attack on a Russian real estate database in January, suggesting a track record of cyber activism targeting Russian infrastructure.
Aeroflot remains one of the world’s top 20 airlines by passenger volume, with 55.3 million passengers flown in 2024, according to its official data. This makes it a high-profile target for political cyberattacks seeking to disrupt Russian infrastructure or damage state-run institutions symbolically and operationally.
Aeroflot’s statement emphasized that specialists were working to restore normal operations and minimize disruptions, but it did not provide a timeline or technical details. There was also no confirmation from the Russian government or its cybersecurity agencies on the nature or attribution of the attack.
The veracity of Silent Crow’s claims — especially regarding the depth of system penetration and the threat to leak personal data — remains unconfirmed. However, the scale of flight cancellations and passenger disruption suggests serious internal system damage, regardless of attribution.

