Security

Cyber-crime

Turbulence at UN aviation agency as probe into potential data theft begins

Crime forum-dweller claims to have leaked 42,000 documents packed with personal info


The United Nations' aviation agency is investigating "a potential information security incident" after a cybercriminal claimed they had laid hands on 42,000 of the branch's documents.

The International Civil Aviation Organization (ICAO) said in a limited statement on Monday that the suspected incident could be linked to "a threat actor known for targeting international organizations."

"We take this matter very seriously and have implemented immediate security measures while conducting a comprehensive investigation," it added.

"Further information will be provided once our preliminary investigation is complete."

The claims were made by an individual using the Natohub alias on a popular cybercrime forum. They claimed the data, which is available to purchase for a nominal fee, includes various personal information on individuals.

Full names, dates of birth, full home addresses, phone numbers, primary and secondary email addresses, marital status, genders, education backgrounds, and employment information are all allegedly compromised.

Natohub has a history of taking credit for attacks on other high profile organizations, such as the US military and the United Nations itself, neither of which ever confirmed the veracity of the leaker's claims.

The Register requested additional updates on the investigation, which the ICAO said began on Monday, but the agency did not respond immediately, although it told Reuters that it wouldn't be commenting any further until its provisional investigation was completed.

The Canada-based agency oversees the aviation relationships between 193 countries, offering technical and diplomatic guidance to ensure innovations in the sector are deployed effectively across the world.

Its last security incident came in 2016 when it became the victim of an attack where watering holes were set up on its own website and that of Turkey's treasury board.

For the uninitiated, a watering hole attack is one where frequently visited sites are poisoned with malware that's then used to gain access to victims' systems.

The details of the incident, however, emerged three years later in a report from public broadcaster CBC, which claimed the ICAO attempted to cover up the incident altogether – a claim the agency's communications chief, Anthony Philbin, didn't deny at the time.

Philbin said the decisions following the event were made after reviewing evidence presented by two outside expert parties and that the agency made "robust improvements" to its cybersecurity posture in response.

The report also alleged that the agency's network was riddled with vulnerabilities that should have been addressed years before the 2016 exploit transpired. ®

Send us news
Post a comment

Rather than add a backdoor, Apple decides to kill iCloud encryption for UK peeps

Plus: SEC launches new crypto crime unit; Phishing toolkit upgraded; and more

Wallbleed vulnerability unearths secrets of China's Great Firewall 125 bytes at a time

Boffins poked around inside censorship engines – here's what they found

Twin Google flaws allowed researcher to get from YouTube ID to Gmail address in a few easy steps

PLUS: DOGE web design disappoints; FBI stops crypto scams; Zacks attacked again; and more!

Trump’s DoD CISO pick previously faced security clearance suspension

Hey, at least Katie Arrington brings a solid resume

Harassment allegations against DEF CON veteran detailed in court filing

More than a dozen women came forward with accusations

DeepSeek's iOS app is a security nightmare, and that's before you consider its TikTok links

PLUS: Spanish cops think they've bagged NATO hacker; HPE warns staff of data breach; Lazy Facebook phishing, and more!

Ransomware criminals love CISA's KEV list – and that's a bug, not a feature

1 in 3 entries are used to extort civilians, says new paper

Signal will withdraw from Sweden if encryption-busting laws take effect

Experts warned the UK’s recent 'victory' over Apple would kickstart something of a domino effect

MITRE Caldera security suite scores perfect 10 for insecurity

Is a trivial remote-code execution hole in every version part of the training, or?

US lawmakers press Trump admin to oppose UK's order for Apple iCloud backdoor

Senator, Congressman tell DNI to threaten infosec agreements if Blighty won't back down

Critical flaws in Mongoose library expose MongoDB to data thieves, code execution

Bugs fixed, updating to the latest version is advisable

Hundreds of Dutch medical records bought for pocket change at flea market

15GB of sensitive files traced back to former software biz