WEEKLY NEWS
SCATTERED SPIDER EXPOSES SECTOR’S SOFT UNDERBELLY
AIR CARG O WEEK
BY Anastasiya SIMSEK
A summer of cyberattacks should have been a wake-up call. For many in the aviation and air cargo sectors, the alarm is still ringing.
In the early summer of 2025, multiple airlines — including WestJet, Hawaiian Airlines, and
04 2 7- 28 April l Rig a, La t v i a
Qantas — reported
cybersecurity
incidents
that disrupted services and raised concerns across the sector. While formal attribution remains tentative,
the tactics mirrored those
used by Scattered Spider, a threat actor known for sophisticated social engineering and ransomware deployment. “The hallmarks were there,” said Lawrence Technical
Baker, Security Consultant
Aerospace Lead at NCC Group. “It’s help desks, again and again. This group
knows how to sound legitimate, create urgency, and trick their way past frontline defences.” The timing wasn’t accidental. With aviation
and
in its summer peak, attackers struck when systems and staf f were stretched — and when disruptions would hurt the most. “It was a prime time to tap these organisations,” “That urgency creates leverage,
Baker noted.
especially in ransomware cases.” Scattered Spider is not new. Active since at
least 2022 and also known under aliases such as Octo Tempest and UNC3944, the group typically floods a sector with attacks before shifting to another. Retail was first, followed by insurance. By mid-2025, aviation became the next target. According to NCC Group’s July report,
aviation’s appeal lies in its high-value data, operational complexity, and interdependence on third-party providers. From passenger
records Prominent speakers:
to crew scheduling, the volume of sensitive information makes the sector ripe for extortion. “The evolution of threats reflects the evolution
of aviation itself,” said Baker. “Where once it was hijacking or smuggling, now it’s identity compromise and MFA fatigue.” Indeed, the industry’s rapid digitalisation —
fuelled by post-COVID recovery and e-commerce surges — has widened the attack surface. Help
desk impersonation, weak multi-factor
authentication protocols, and remote access vulnerabilities
have become common entry
points. “What they may do is look at LinkedIn or other
online sources to identify high-profile targets within airlines, such as chief financial of ficers, for example, and then impersonate that person. They may contact a third-party IT service
Host partners: Co-Host partners:
provider’s help desk and ask for the account to be reset, pretending to be that person.” Even
basic Gold sponsors: Silver sponsors: Organizer: controls are often through psychological pressure.
kind of sense of urgency and pressure, they can just convince the help desk staff to then just reset the account anyway.”
Lead Media Partner: Media Partners:
Inside the attack chain Scattered Spider’s method is not brute force — it relies on behavioural exploitation. The group depends
on For more information, exhibition and registration online:
www.nordicaircargosymposium.com ACW 16 MARCH 2026 research, patience, and subtle
manipulation. They start by profiling targets through LinkedIn
www.aircargoweek.com bypassed “Through that
or open sources. From there, phishing emails, fake login pages, and domain impersonation are deployed. Once inside, attackers use tools like AnyDesk or LogMeIn to move laterally, access sensitive data, and escalate privileges. “They
exploit repeated multi-factor
authentication prompts, causing MFA fatigue.” The result is swift. “The group has breached
organisations, established persistent access, exfiltrated data,
and detonated ransomware
within a matter of hours.” Qantas, for instance, confirmed unauthorised
access to its call centre platform, exposing personal data of over six million passengers. Hawaiian Airlines reported a non-critical IT incident. WestJet’s mobile
app was briefly
disabled. While few operational disruptions were publicised, the real damage — data exposure, trust erosion, regulatory risk — will take longer to surface. Third-party vendors were also likely vectors.
The heavy outsourcing of IT and ground systems in air logistics makes supply chain compromise a real concern. Despite years of cybersecurity briefings, most
aviation firms remain underprepared for attacks like this. “Acting quickly is key,” Baker said. “Having
those provisions in place in advance is absolutely fundamental.” The weakest point
is often the help desk,
where identity verification is rushed or poorly enforced. Many
organisations have no contractual lack phishing-
resistant MFA, fail to audit dormant accounts, and
arrangements with
external incident response teams. Proactive monitoring is also lacking. Few
teams are equipped to detect subtle indicators — such as remote access activating, MFA reassignments,
resets from unrecognised geographies. NCC
Group’s recommendations include
identity verification via live video with ID, just- in-time access controls for admin accounts, and rigorous audit trails for vendor systems. Still, Baker says, the deeper fix is strategic. “You’re not going to fix this overnight,” Baker
said. “It’s about putting in place a plan you can execute over time.” For the air cargo industry, the message is
clear: cybersecurity is no longer an IT problem. It’s an operational risk — as real and immediate as weather, fuel, or customs.
tools quietly or password
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16