The Everest ransomware group has added Dubai-based low-cost carrier FlyDubai to its dark web leak site. The group claims it stole about 4.36GB of data, including pilot training materials, crew personnel records and proprietary Boeing software source code. This is a threat actor's claim and has not been verified. FlyDubai has not confirmed an intrusion. None of the available sources is a primary source: there is no statement from the airline, no regulator filing and no national CERT advisory. Hackmanac lists the claim as "pending verification," according to Rescana. Cybernews reports that Everest has not published sample screenshots to back it up. No ransom amount has been made public.
What Happened
ThreatMon's dark web monitoring found Everest's FlyDubai listing at about 17:03 UTC+3 on October 6, 2026, according to Undercode News. Everest added US industrial manufacturer Kennametal to its victim list within minutes. Nothing available shows that the two claims are connected. Hackmanac reported the FlyDubai claim the same day (via Rescana), and Breaking The News carried it that afternoon.
Cybernews says Everest put a six-day countdown on the listing to pressure FlyDubai into negotiating. This is a standard extortion tactic. If the timer started at the time of listing, a leak could come around October 12.
The claim comes one week after an unrelated and highly visible incident at the airline. On September 30, flight FZ1073 from Dubai to Tel Aviv diverted to Tabuk, Saudi Arabia, after an attack on the flight deck. FlyMag and the Indian Express report that the co-pilot attacked the captain mid-flight. FlyDubai then suspended all Israel flights while authorities investigate. No source links the cockpit attack to the Everest claim. Defenders should still expect threat actors to take advantage of the attention the airline is getting.
What Was Taken
All of the following comes from Everest's own listing and has not been independently confirmed.
- Volume: Everest claims about 4.36GB. Sources count it in different units. Rescana, citing Hackmanac, puts it at 16,517 files. Cybernews reports 17,053 records covering 2,862 employees. Rescana counts files and Cybernews counts personnel records, so the figures are not necessarily in conflict. Neither has been verified.
- Personnel data: Cybernews lists full names, employee IDs, job titles, employment start and end dates, training completion dates and qualification check records. The records reportedly cover pilots, cabin crew, training managers, technical pilots, dispatchers and ground staff.
- Time span: The records reportedly date from 2009 to 2020 (Cybernews). That suggests an older archive or legacy system rather than current HR data.
- Operational material: The listing claims pilot training materials, operational directives, flight operations documents and crew training documents (Cybernews, Rescana).
- Third-party IP: Everest claims to hold Boeing software source code and confidential aviation documents. Boeing has not commented in any of the sources, and nothing shows how FlyDubai would have held such code or what it covers.
Why It Matters
- Crew-targeted social engineering: Cybernews researchers note that names, roles, employee IDs and qualification histories are well suited to phishing and impersonation aimed at flight crew. Many of those people have since moved to other carriers in the region.
- Exposure through the supply chain: If the Boeing code claim is true, the risk extends to the manufacturer and potentially to other 737 operators. It would also raise questions about how OEM intellectual property is stored and controlled by operators. Until there is evidence, treat this part of the claim with the most skepticism, because ransomware groups often exaggerate their headline material.
- Aviation in the Gulf is under pressure: Unit 42 reports, via GBHackers, that an Iranian state-aligned actor (CL-STA-1178) posed as Dubai Airports recruiters and used fake coding tests to deliver ShelbyLoader V2 to software engineers. Unit 42 found no compromise of Dubai Airports and nothing connects that campaign to Everest. It does show that the region's aviation brands are being used as lures.
- Old data still carries risk: Retention is a factor here. Data that is 6 to 17 years old is still valuable to attackers, and it raises regulatory questions about why it was kept.
The Attack Technique
The intrusion method is unknown. Rescana states plainly that no source has identified the exploited system, the vulnerability, a compromised credential or a third-party access path. No root cause should be assumed. It is also unclear whether any systems were encrypted or whether this was data theft and extortion only.
For background, Everest is a long-running operation that has increasingly relied on data-theft extortion and initial-access brokering. Its past intrusions have often used valid credentials and remote access tools. That is general context about the group, not evidence of how this incident happened.
What Organizations Should Do
- Warn current and former crew: Tell flight operations and HR staff, including people who left after 2009, to expect targeted phishing that uses their employee IDs, ranks and training history.
- Audit legacy training and HR stores: Find old crew-training and qualification archives, especially those predating 2020. Restrict access to them and either delete them or move them to segregated storage under clear retention rules.
- Check access to OEM intellectual property: Inventory where manufacturer software, tools and documentation sit inside your environment. Enforce least-privilege access and log every access.
- Hunt for data leaving the network: Look at outbound transfers in the GB range to cloud storage or unusual destinations, unexpected archiving tools such as rclone or 7-Zip, and use of remote access software outside approved windows.
- Harden remote access: Require phishing-resistant MFA on VPNs, VDI and RDP gateways. Rotate credentials for service accounts and contractor accounts.
- Treat recruitment lures as a threat vector: As the ShelbyLoader V2 campaign shows, block or sandbox untrusted Visual Studio and MSBuild project files, and teach engineers that opening a "coding test" can execute code.
Sources: FlyDubai Ransomware Attack Threatens Pilot Data and Boeing Code Cy... | FlydubaiEverestBreachClaim... | Everest Ransomware Claims Flydubai and Kennametal as New Victims, R... | Everest hackers claim breach of Flydubai data - Breaking The News | Flydubai co-pilot attack: What went wrong in Israel, Oman, UAE | Flydubai Suspends Israel Flights After FZ1073 Cockpit Attack - FlyM... | Hannan Shah | Hackers Pose as Dubai Airports Recruiters to Infect Software Engine...