Data Breach

American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign

Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle’s E-Business Suite (EBS).

The breach, first highlighted by the notorious Clop ransomware group, underscores the growing risks facing enterprise software in the aviation sector.

Clop, known for high-profile extortion schemes like the MOVEit Transfer attacks, claimed responsibility last week, listing American Airlines among over 60 organizations hit through unpatched flaws in Oracle EBS.

The group, which operates out of Russia-linked networks, has demanded ransoms in cryptocurrency, threatening to leak stolen data on its dark web site if unpaid.

While Clop didn’t specify the exact vulnerabilities, security researchers point to known issues in Oracle’s WebLogic Server and EBS modules, such as CVE-2023-21931, which allow remote code execution if not properly secured.

Envoy’s admission came swiftly after the claims surfaced, aiming to reassure stakeholders amid rising concerns over aviation data security.

Envoy Compromised

“We are aware of the incident involving Envoy’s Oracle E-Business Suite application,” an Envoy spokesperson told Cybersecurity News. “Upon learning of the matter, we immediately began an investigation and law enforcement was contacted”.

“We have conducted a thorough review of the data at issue and have confirmed no sensitive or customer data was affected. A limited amount of business information and commercial contact details may have been compromised.”

The spokesperson emphasized that passenger records, flight operations, and personal identifiable information remained untouched, mitigating immediate risks to travelers.

However, the exposure of internal business data could still pose challenges, including potential phishing vectors or competitive intelligence leaks for the regional carrier, which operates over 150 aircraft and serves millions of passengers annually under the American Airlines banner.

Experts warn that this incident highlights systemic vulnerabilities in legacy enterprise systems. Oracle EBS, widely used for HR, finance, and supply chain management, has faced criticism for slow patching cycles.

Cybersecurity firm Mandiant noted in a recent report that Clop’s tactics often target third-party software to amplify reach, affecting not just direct victims but entire ecosystems.

As investigations continue with federal authorities, including the FBI’s cyber division, Envoy stated it has implemented enhanced monitoring and updated its Oracle systems. American Airlines, while not directly named in data leaks, has bolstered its subsidiary’s defenses in response.

This breach arrives amid a wave of aviation cyberattacks, from ransomware hitting airports to state-sponsored espionage. Industry leaders are urging faster adoption of zero-trust architectures to safeguard critical infrastructure.

For now, Envoy passengers can fly with relative peace of mind, but the event serves as a stark reminder: in cybersecurity, one weak link can ground an entire operation.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago