Airlines Are The Next Big Targets For Cybercrime

Airlines Are The Next Big Targets For Cybercrime

No one really knows why airlines have become a target as of late but with the rate of attacks this high, something is definitely going on.

Not too long ago cybercriminals operated within fairly predictable parameters by targeting large corporations with ransomware. Alongside this, ‘petty’ cybercriminals targeted smaller organisations and individuals for not much more than pure disruption. In recent years, however, cyber-attacks have grown more chaotic with the range of targets growing to movie studios, governments, universities, and airlines – objectives of these attacks are widening too. Airlines are suffering hugely, with the number of attacks in 2017 and 2018 increasing by a staggering 15,000%.

Oddly, no one really knows why airlines have become a target as of late but with the rate of attacks this high, something is definitely going on. An infographic by Sungard AS, provider of IT production and recovery services, shows that the frequency of attacks is steadily increasing. Taking stock of all airline outages form 2007 to present day, Sungard found that 2015 suffered a total of 11 outages and 2018 saw 10 outages disrupt air travel. This year alone has already seen 3 outages, with many more predicted in the months ahead.

Southwest Airlines suffered an outage that grounded flights all across the US, causing disruptions to passengers though it was fairly short lived. Still, a disruption of any length disturbs operations and negatively impacts brand image. Consumers, especially ones in high-stress situations like air travel, are always going to blame the airline if their flight is grounded, even if the issue was truly unexpected.

So, what might be behind these continued outages? Some seem to be caused by what is known in the industry as Distributed Denial of Service (DDoS) attacks, where a host connected to the Internet is disrupted. There’s an immediacy to airline disruptions that cybercriminals are likely to appreciate as flights are grounded, passengers are left frustrated, and it all has a knock-on effect on service, even if the outage was short-lived.

The outages aren’t always so large-scale. In some instances, DDoS attacks take on subtler forms by making the booking process and airline site loading time sluggish, leading to failed transactions, which all translates to needless expenditure of resources.

Hackers’ motivations are difficult to diagnose when it comes to targeting airlines as they’re always some combination of extortion, competition, and even plain ‘because why not-ism’. One thing is clear, airlines are continually targeted because they’re so reliant on computer networks. Netscout compared the size of the attacks finding that in 2018 the maximum-recorded size of an attack reached 245 Gbps (billions of bits per second, a measure of internet bandwidth) - in 2016, the maximum attack size was 124 Gbps. The increase can only be categorised as severe, with more on the horizon.

Companies big and small must start to take their cyber security seriously as there’s no sign of the cybercrime rates going down. Predictions for the year ahead and beyond are sure that it’s only going to get worse with cybercriminals no longer being motivated by money alone – political unrest and pure disruption for disruption’s sake are as favourable of outcomes as cash payments.

About the Author

Matthew Walker-Jones specialises in informative content covering topics such as data driven marketing, online data protection, data recovery and cyber security.

Featured

  • UL Solutions Launches Artificial Intelligence Safety Certification Services

    UL Solutions Inc., a global leader in safety science, today announced the launch of artificial intelligence (AI) safety certification services, enabling comprehensive assessments for evaluating the safety of AI-powered products. Read Now

  • ESA Announces Initiative to Introduce the SECURE Act in State Legislatures

    The Electronic Security Association (ESA), the national voice for the electronic security and life safety industry, has announced plans to introduce the SECURE Act in state legislatures across the country beginning in 2025. The proposal, known as Safeguarding Election Candidates Using Reasonable Expenditures, provides a clear framework that allows candidates and elected officials to use campaign funds for professional security services. Read Now

    • Guard Services
  • Ransomware Attacks Rise for the First Time in Six Months

    Ransomware attacks have risen for the first time in six months, increasing by 28% month-on-month to 421 attacks. While overall attack volume remained below 500, the uptick may signal a renewed escalation heading into the year’s most active period for cyber criminals. Read Now

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.