Airlines Are The Next Big Targets For Cybercrime

Airlines Are The Next Big Targets For Cybercrime

No one really knows why airlines have become a target as of late but with the rate of attacks this high, something is definitely going on.

Not too long ago cybercriminals operated within fairly predictable parameters by targeting large corporations with ransomware. Alongside this, ‘petty’ cybercriminals targeted smaller organisations and individuals for not much more than pure disruption. In recent years, however, cyber-attacks have grown more chaotic with the range of targets growing to movie studios, governments, universities, and airlines – objectives of these attacks are widening too. Airlines are suffering hugely, with the number of attacks in 2017 and 2018 increasing by a staggering 15,000%.

Oddly, no one really knows why airlines have become a target as of late but with the rate of attacks this high, something is definitely going on. An infographic by Sungard AS, provider of IT production and recovery services, shows that the frequency of attacks is steadily increasing. Taking stock of all airline outages form 2007 to present day, Sungard found that 2015 suffered a total of 11 outages and 2018 saw 10 outages disrupt air travel. This year alone has already seen 3 outages, with many more predicted in the months ahead.

Southwest Airlines suffered an outage that grounded flights all across the US, causing disruptions to passengers though it was fairly short lived. Still, a disruption of any length disturbs operations and negatively impacts brand image. Consumers, especially ones in high-stress situations like air travel, are always going to blame the airline if their flight is grounded, even if the issue was truly unexpected.

So, what might be behind these continued outages? Some seem to be caused by what is known in the industry as Distributed Denial of Service (DDoS) attacks, where a host connected to the Internet is disrupted. There’s an immediacy to airline disruptions that cybercriminals are likely to appreciate as flights are grounded, passengers are left frustrated, and it all has a knock-on effect on service, even if the outage was short-lived.

The outages aren’t always so large-scale. In some instances, DDoS attacks take on subtler forms by making the booking process and airline site loading time sluggish, leading to failed transactions, which all translates to needless expenditure of resources.

Hackers’ motivations are difficult to diagnose when it comes to targeting airlines as they’re always some combination of extortion, competition, and even plain ‘because why not-ism’. One thing is clear, airlines are continually targeted because they’re so reliant on computer networks. Netscout compared the size of the attacks finding that in 2018 the maximum-recorded size of an attack reached 245 Gbps (billions of bits per second, a measure of internet bandwidth) - in 2016, the maximum attack size was 124 Gbps. The increase can only be categorised as severe, with more on the horizon.

Companies big and small must start to take their cyber security seriously as there’s no sign of the cybercrime rates going down. Predictions for the year ahead and beyond are sure that it’s only going to get worse with cybercriminals no longer being motivated by money alone – political unrest and pure disruption for disruption’s sake are as favourable of outcomes as cash payments.

About the Author

Matthew Walker-Jones specialises in informative content covering topics such as data driven marketing, online data protection, data recovery and cyber security.

Featured

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.