Cyber & AI intelligence
Wasteland.
Briefs indexed3039
Issues31
Published Mondays07:30 CT
█ Ransomware FLYDUBAI-RANSOMWAR 2026-10-07

FlyDubai: Everest Ransomware Claims Theft of Pilot Data and Boeing Code

"The Everest ransomware group has added Dubai-based low-cost carrier FlyDubai to its dark web leak site. The group claims it stole about 4.36GB of data, including pilot training materials, crew personnel records and…"

The Everest ransomware group has added Dubai-based low-cost carrier FlyDubai to its dark web leak site. The group claims it stole about 4.36GB of data, including pilot training materials, crew personnel records and proprietary Boeing software source code. This is a threat actor's claim and has not been verified. FlyDubai has not confirmed an intrusion. None of the available sources is a primary source: there is no statement from the airline, no regulator filing and no national CERT advisory. Hackmanac lists the claim as "pending verification," according to Rescana. Cybernews reports that Everest has not published sample screenshots to back it up. No ransom amount has been made public.

What Happened

ThreatMon's dark web monitoring found Everest's FlyDubai listing at about 17:03 UTC+3 on October 6, 2026, according to Undercode News. Everest added US industrial manufacturer Kennametal to its victim list within minutes. Nothing available shows that the two claims are connected. Hackmanac reported the FlyDubai claim the same day (via Rescana), and Breaking The News carried it that afternoon.

Cybernews says Everest put a six-day countdown on the listing to pressure FlyDubai into negotiating. This is a standard extortion tactic. If the timer started at the time of listing, a leak could come around October 12.

The claim comes one week after an unrelated and highly visible incident at the airline. On September 30, flight FZ1073 from Dubai to Tel Aviv diverted to Tabuk, Saudi Arabia, after an attack on the flight deck. FlyMag and the Indian Express report that the co-pilot attacked the captain mid-flight. FlyDubai then suspended all Israel flights while authorities investigate. No source links the cockpit attack to the Everest claim. Defenders should still expect threat actors to take advantage of the attention the airline is getting.

What Was Taken

All of the following comes from Everest's own listing and has not been independently confirmed.

Why It Matters

The Attack Technique

The intrusion method is unknown. Rescana states plainly that no source has identified the exploited system, the vulnerability, a compromised credential or a third-party access path. No root cause should be assumed. It is also unclear whether any systems were encrypted or whether this was data theft and extortion only.

For background, Everest is a long-running operation that has increasingly relied on data-theft extortion and initial-access brokering. Its past intrusions have often used valid credentials and remote access tools. That is general context about the group, not evidence of how this incident happened.

What Organizations Should Do

  1. Warn current and former crew: Tell flight operations and HR staff, including people who left after 2009, to expect targeted phishing that uses their employee IDs, ranks and training history.
  2. Audit legacy training and HR stores: Find old crew-training and qualification archives, especially those predating 2020. Restrict access to them and either delete them or move them to segregated storage under clear retention rules.
  3. Check access to OEM intellectual property: Inventory where manufacturer software, tools and documentation sit inside your environment. Enforce least-privilege access and log every access.
  4. Hunt for data leaving the network: Look at outbound transfers in the GB range to cloud storage or unusual destinations, unexpected archiving tools such as rclone or 7-Zip, and use of remote access software outside approved windows.
  5. Harden remote access: Require phishing-resistant MFA on VPNs, VDI and RDP gateways. Rotate credentials for service accounts and contractor accounts.
  6. Treat recruitment lures as a threat vector: As the ShelbyLoader V2 campaign shows, block or sandbox untrusted Visual Studio and MSBuild project files, and teach engineers that opening a "coding test" can execute code.

Sources: FlyDubai Ransomware Attack Threatens Pilot Data and Boeing Code Cy... | FlydubaiEverestBreachClaim... | Everest Ransomware Claims Flydubai and Kennametal as New Victims, R... | Everest hackers claim breach of Flydubai data - Breaking The News | Flydubai co-pilot attack: What went wrong in Israel, Oman, UAE | Flydubai Suspends Israel Flights After FZ1073 Cockpit Attack - FlyM... | Hannan Shah | Hackers Pose as Dubai Airports Recruiters to Infect Software Engine...