Aeroflot hit by major cyberattack: Silent Crow claims breach of 7,000 servers, threatens passenger data leak

On Monday, Russian national carrier Aeroflot was forced to cancel over 40 flights following a major disruption in its information systems, which the airline described as a system failure.

Aeroflot cyber security
Aeroflot cyber security
Credit – Facebook

However, a hacker collective named Silent Crow, allegedly working in coordination with a Belarusian cyber activist group called Cyberpartisans BY, claimed responsibility for what they characterized as a coordinated and crippling cyberattack.

While Aeroflot did not disclose the specific cause or technical nature of the disruption, the hacking group Silent Crow released a statement — unverified by Reuters — claiming the attack had:

Been in planning and execution for over a year.

Resulted in the destruction of 7,000 servers.

Gained deep access to Aeroflot’s internal network, including control over the personal computers of employees, notably senior executives.

The attackers also threatened to leak personal data of every individual who has flown with Aeroflot, suggesting potential exposure of millions of passengers’ information, including Russian citizens and international travelers. If true, this could represent a severe breach of personal privacy and national aviation security.

The immediate impact was widespread flight cancellations, with Aeroflot listing over 40 affected routes, including domestic flights and services to Minsk (Belarus) and Yerevan (Armenia). The airline urged passengers departing from Moscow’s Sheremetyevo Airport to collect their checked-in baggage and leave the terminal, Reuters news report said on Monday.

Reports from the independent news outlet Baza described chaotic scenes at Sheremetyevo, with passengers stuck in queues and airport operations severely hampered. This underscores the dependence of modern airline infrastructure on digital systems and the cascading effects when they are compromised.

Silent Crow had earlier claimed responsibility for an attack on a Russian real estate database in January, suggesting a track record of cyber activism targeting Russian infrastructure.

Aeroflot remains one of the world’s top 20 airlines by passenger volume, with 55.3 million passengers flown in 2024, according to its official data. This makes it a high-profile target for political cyberattacks seeking to disrupt Russian infrastructure or damage state-run institutions symbolically and operationally.

Aeroflot’s statement emphasized that specialists were working to restore normal operations and minimize disruptions, but it did not provide a timeline or technical details. There was also no confirmation from the Russian government or its cybersecurity agencies on the nature or attribution of the attack.

The veracity of Silent Crow’s claims — especially regarding the depth of system penetration and the threat to leak personal data — remains unconfirmed. However, the scale of flight cancellations and passenger disruption suggests serious internal system damage, regardless of attribution.

0 0 votes
Article Rating
Baburajan Kizhakedath
Baburajan Kizhakedath
Baburajan Kizhakedath is the editor of InfotechLead.com. He has three decades of experience in tech media.
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted

Latest

More like this
Related

7 MDR Solutions for Converged IT and OT Security Operations

The most dangerous incident in a connected industrial enterprise...

AI Ransomware Costs Just $4 Per Target as Automated Attacks Raise Million-Dollar Enterprise Risks

Artificial intelligence is lowering the cost and technical barriers...

CrowdStrike Revenue Rises 26% to $1.47 Billion as AI Security Demand Lifts FY27 Forecast

CrowdStrike has raised its fiscal 2027 revenue forecast after...