https://www.theregister.com/2023/11/10/lockbit_leaks_boeing_files/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Cloud Infrastructure Week Cybersecurity Month Blackhat and DEF CON Sysadmin Month The Reg in Space Emerging Clean Energy Tech Week Spotlight on RSA Energy Efficient Datacenters Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business TransformationDDN Google Cloud Data TransformationGoogle Cloud InfrastructureGoogle WorkspaceHewlett Packard Enterprise: AI & ML solutionsHewlett Packard Enterprise: Edge-to-Cloud PlatformIntel vProVMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [cybercrime] Cyber-crime 10 comment bubble on white Impatient LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land 10 comment bubble on white Aerospace titan pores over data to see if dump is legit icon Jessica Lyons Hardcastle Fri 10 Nov 2023 // 20:21 UTC # The LockBit crew is claiming to have leaked all of the data it stole from Boeing late last month, after the passenger jet giant apparently refused to pay the ransom demand. The gang dumped the files online early Friday morning. This latest leak includes about 50GB of data in the form of compressed archives and backup files for various systems. The full release comes after the extortionists uploaded some files said to be related to company finances and marketing activities as well as supplier details. [cybercrime] Screenshots of the stolen info showed several Citrix logs, which has led to some speculation that LockBit exploited Citrix Bleed to break into the defense contractor's systems. Boeing has so far refused to comment on the initial point of entry into its systems. [cybercrime] [cybercrime] Neither data dump has been verified by The Register, and Boeing declined to answer specific questions about the incident or the stolen files. A spokesperson sent us this comment via email: Elements of Boeing's parts and distribution business recently experienced a cybersecurity incident. We are aware that, in connection with this incident, a criminal ransomware actor has released information it alleges to have taken from our systems. We continue to investigate the incident and will remain in contact with law enforcement, regulatory authorities, and potentially impacted parties, as appropriate. We remain confident this incident poses no threat to aircraft or flight safety. According to security researcher Dominic Alvieri, the files also contained corporate emails. "I haven't gone over the whole data set but Boeing emails and a few others stand out as useful for those with malicious intent," Alvieri told The Register. * Boeing acknowledges cyberattack on parts and distribution biz * 'Mass exploitation' of Citrix Bleed underway as ransomware crews pile in * China's top bank ICBC hit by ransomware, derailing global trades * Strangely enough, no one wants to buy a ransomware group that has cops' attention LockBit first listed the aircraft giant on its dark-web site on October 28, and on November 2 Boeing confirmed to The Register it had suffered an IT intrusion. At the time, a spokesperson said the break-in affected the manufacturer's parts and distribution business. By then, however, the ransomware crew had removed Boeing from its leaks site and told the malware librarians at VX Underground that it was negotiating with the US corporation. It appears that the negotiations failed -- or possibly the multinational determined that the criminals hadn't accessed any sensitive info, and thus it wouldn't pay to pay the extortion demand, or no talks ever actually took place -- and Boeing is now back on the LockBit extortion website Also this week, China's largest bank, ICBC, was hit by a ransomware attack that disrupted financial services systems on Thursday Beijing time. LockBit told VX-Underground that it was was responsible for this break-in, too. (r) Get our Tech Resources # Share More about * Boeing * Cybercrime * Ransomware More like these x More about * Boeing * Cybercrime * Ransomware * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * Boeing AH-64 Apache * BSides * Bug Bounty * Common Vulnerability Scoring System * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Encryption * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Remote Access Trojan * REvil * RSA Conference * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust Broader topics * Aerospace * Defense More about # Share 10 comment bubble on white COMMENTS More about * Boeing * Cybercrime * Ransomware More like these x More about * Boeing * Cybercrime * Ransomware * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * Boeing AH-64 Apache * BSides * Bug Bounty * Common Vulnerability Scoring System * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Encryption * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Remote Access Trojan * REvil * RSA Conference * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust Broader topics * Aerospace * Defense TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like US officials close to persuading allies to not pay off ransomware crooks 'We're still in the final throes of getting every last member to sign' Cyber-crime31 Oct 2023 | 21 Stanford schooled in cybersecurity after Akira claims ransomware attack This marks the third criminal intrusion at the institution in as many years Cyber-crime30 Oct 2023 | 3 Get your very own ransomware empire on the cheap, while stocks last RansomedVC owner takes to Telegram to flog criminal enterprise Cyber-crime1 Nov 2023 | 5 Automating generative AI development GenAI and powerful server hardware supports quick design, build and delivery of new AI applications and models Sponsored Feature [cybercrime] Hunters International leaks pre-op plastic surgery pics in negotiation no-no No honor among thieves as group denies Hive ransomware links Cyber-crime25 Oct 2023 | 6 81K people's sensitive info feared stolen from Hilb after email inboxes ransacked Credit card numbers, security codes, SSNs, passwords, PINs? Yikes! Cyber-crime3 Nov 2023 | 3 Strangely enough, no one wants to buy a ransomware group that has cops' attention Ransomed.vc shuts after 20% discount fails to entice bids Cyber-crime10 Nov 2023 | 4 Microsoft: Iran's cybercrews got stuck into Israel days after Hamas attacked - not in tandem At least two destructive attacks, but - crucially - after deadly conflict erupted Public Sector10 Nov 2023 | 18 Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit Gang thought to be behind attack on MGM Resorts has a skillset larger than most cybercrime groups in existence Research27 Oct 2023 | 1 Okta tells 5,000 of its own staff that their data was accessed in third-party breach Updated The hits keep on coming for troubled ID management biz Cyber-crime2 Nov 2023 | 28 Ransomware crooks SIM swap medical research biz exec, threaten to leak stolen data Advarra probes intrusion claims, says 'the matter is contained' Cyber-crime1 Nov 2023 | 6 Russia's Sandworm - not just missile strikes - to blame for Ukrainian power blackouts Online attack coincided with major military action, Mandiant says Security9 Nov 2023 | 26 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2023 no-js