Top aircraft provider hit by ransomware, with 1TB data cache possibly stolen

security
(Image credit: Shutterstock / binarydesign)

One of the biggest aircraft leasing companies in the world has apparently suffered a ransomware attack that resulted in the theft of sensitive corporate data. 

AerCap appeared to confirm the news in a 6-K form filed with the U.S. Securities and Exchange Commission (SEC) in which it experienced a “cybersecurity incident related to ransomware” on January 17.

The company has keen to play down the effect of the incident, noting, “We have full control of all of our IT systems and to date, we have suffered no financial loss related to this incident."

Who is Slug?

The company is currently investigating the incident and looking to understand “the extent to which data may have been exfiltrated or otherwise impacted”. An expert third-party cybersecurity company was brought in to assist with the investigation, AerCap said, adding that law enforcement was notified of the breach.

While the company did not say who the attackers were or what they were after, the HackManac project claims to have found the culprit - a new entrant in the ransomware landscape called Slug, The Register discovered.

In an X post published earlier this week, HackManac said Slug pulled a terabyte of sensitive data from AerCap’s endpoints. “This data is threatened to be progressively released over a two-week period should an agreement not be reached,” the post reads.

Very little is known about Slug as a threat actor. Its website “remains bare”, HackManac said, leaving no further information about the group. Its logo is a picture of the blue sea dragon. 

The details about the stolen data also remain a mystery, as well as the group’s ransom demands. Given that AerCap seems to have restored its systems fully, it is highly unlikely the company will pay the attackers. 

Headquartered in Dublin, the company’s biggest customer is American Airlines, the media found.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Red padlock open on electric circuits network dark red background
Aviation firms hit by devious new polyglot malware
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Code Skull
Top component maker Unimicron hit by massive ransomware attack
Password
Millions of airline customers possibly affected by OAuth security flaw
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Latest in Security
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Latest in News
An image of the Nintendo Switch 2
Nintendo Switch 2 pre-orders will start on April 2 according to Best Buy Canada
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long
Screenshot from action RPG soulslike Lies of P
Lies of P Overture won't elaborate on the game's eyebrow-raising post-credits twist, and I think that's good news
Nintendo Switch 2
The Switch 2 launching with a Mario Kart game 'is very unlike Nintendo' compared to the original Switch releasing with Breath of the Wild, says former marketing leads: 'That's what's gonna make you want to buy the new hardware'