FBI, cybersecurity firms say a prolific hacking crew is now targeting airlines and the transportation sector


The FBI and cybersecurity firms are warning that the prolific hacking group known as Scattered Spider is now targeting airlines and the transportation sector.

In a brief statement on Friday shared with TechCrunch, the FBI said it had “recently observed” cyberattacks resembling Scattered Spider to include the airline sector. Executives from Google’s cybersecurity unit Mandiant and Palo Alto Networks’ security research division Unit 42 also said they have witnessed Scattered Spider cyberattacks targeting the aviation industry. Scattered Spider is a collective of mostly English-speaking hackers, typically teenagers and young adults, who are financially motivated to steal and extort sensitive data from company networks.

Read more…
Source:TechCrunch News


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach

    October 5, 2026

    A major cybersecurity breach has exposed the personal data of 8.8 million people in Denmark. Denmark has suffered a major data breach after hackers broke into the country’s national population registry and accessed the personal information of millions of people. The country’s digital affairs minister announced the data breach on Monday, calling it “an extremely serious incident” ...

  • ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau

    October 3, 2026

    A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif ‌al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...

  • Fortinet sounds the alarm over actively exploited FortiMail zero-day

    October 2, 2026

    Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet’s email security platform. Fortinet describes the vulnerability as a combination of path traversal and ...

  • SMTP is the key: BPFDoor and AVERAT hitting the network edge

    October 2, 2026

    Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...

  • Operation KillSwitch: Teenager suspected of leading KillSec ransomware group

    October 1, 2026

    On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German ...

  • ShinyHunters hackers are going after Oracle systems once again

    September 29, 2026

    ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited – so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations. In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java ...