
The Everest ransomware group has reportedly published a portion of data it claims to have stolen from the servers of Flydubai and Boeing, raising concerns about data security and the potential risks to the aviation industry. The alleged breach involves sensitive employee information and proprietary aviation-related technical data, which could be exploited for phishing attacks, social engineering fraud, and other malicious activities.
Flydubai recently attracted media attention following reports of a hijack threat involving one of its aircraft, which was reportedly handled through the courageous actions of its senior pilot, Smith Machchhar. However, the latest development has shifted attention toward the airline’s Cybersecurity posture and the potential exposure of confidential information.
According to claims made by Everest, approximately 4.36 GB of data was allegedly exfiltrated from Flydubai’s systems. The leaked material reportedly contains around 2,862 employee profiles and 17,000 records. The information is said to include employee names, job titles, identification numbers, training dates, and details concerning pilots’ qualifications and educational backgrounds.
Although such information may not directly compromise aircraft operations, its exposure could create significant security risks. Cyber criminals could use these details to craft convincing phishing emails, impersonate airline personnel, or target employees with carefully designed social engineering campaigns. Information relating to pilot qualifications and training could also be misused to create fraudulent communications or impersonation attempts.
In a separate claim, a Telegram source reportedly shared a link to information allegedly associated with Boeing’s Performance Engineers Tool, known as PET 3.2. The tool reportedly contains technical parameters such as takeoff weight, landing distance, fuel consumption, obstacle clearance, and engine-out performance details. If the authenticity of the exposed material is established, the incident could raise concerns about the disclosure of Boeing’s proprietary engineering information and the potential misuse of sensitive technical data.
The alleged stolen information has reportedly been made available through a dark-web resource associated with Everest ransomware. The group, described in the report as having Russian links, had reportedly remained inactive since January 2026 before resurfacing with these claims.
The European Union Aviation Safety Agency (EASA) has reportedly taken note of the incidents. Any further response is expected to depend on the findings of detailed investigations by the affected organizations and the submission of relevant reports.
At this stage, the allegations require independent verification. Until the investigations establish the extent and authenticity of the purported data theft, the claims should be treated with caution. Nevertheless, the incident highlights the importance of robust cyber security controls, timely threat detection, and the protection of sensitive employee and engineering data across the global aviation sector.
Join our LinkedIn group Information Security Community!










