The LockBit ransomware gang has reportedly published data that was stolen from American commercial and defense aircraft manufacturer Boeing .

Before the leak, hackers from the LockBit group said Boeing ignored warnings about publishing the data , so they threatened to publish a sample of about 4GB of the most recent files.
Backup data published
The gang leaked more than 43 GB of files from Boeingafter the company refused to pay the ransom. Most of the data listed on the leak site are backups for various systems. The most recent of these is timestamped on October 22.
See also: McLaren Health Care: Data breach affected 2.2 million people
The hackers added Boeing's name to their website on October 27 and gave the company until November 2 to contact them and engage in negotiations. The LockBit ransomware gang said at the time that it had stolen "a huge amount of sensitive data."
Boeing disappeared from the list of LockBit victims for a period, but was re-listed on November 7th, when the hackers announced that their warnings had been ignored.
The company appears to have made no move, leading the hackers to try to escalate the situation, threatening to release “sample data (the most recent) about 4 GB.” They also said they would release the databases “if they don’t see cooperation from Boeing.”
On November 10, the LockBit ransomware gang posted on its website all the data it had stolen from Boeing. Among the files are backups of settings for IT management software and logs for monitoring and auditing tools.
There are also backups from Citrix devices , which has sparked speculation about the use of the recently disclosed Citrix Bleed vulnerability (CVE-2023-4966).
See also: Chess.com: Hacker exposes data of more than 800,000 users
While Boeing confirmed the cyberattack, it has not provided details about the incident or how the hackers breached its network.
LockBit is one of the most persistent ransomware-as-a-service (RaaS) operations. It has been used in attacks for more than four years and has successfully targeted thousands of victims across a variety of sectors. Victims include Continental, the Royal Mail ’s UK, the Italian Inland Revenue Service, and the City of Auckland.
The US government said in June that the gang had extorted about $91 million from victims since 2020 in 1,700 attacks in the country.
However, the gang is targeting organizations worldwide. In August, the Spanish National Police warned of a phishing campaign targeting architecture firms to encrypt systems with the LockBit malware.

Consequences of the Boeing data leak
The potential consequences of Boeing's data breach could be serious and damaging to the company. First, the leak of confidential data could cause serious damage to its reputation and standing. The trust of customers, business partners, and the public could be undermined, as the leak shows that the company is unable to protect its own and its customers' confidential data.
See also: Kyocera AVX (KAVX): Ransomware attack led to data breach
Furthermore, data leaks can have serious implications for flight safety and aviation security in general. If the leaks include sensitive information about Boeing's aircraft technology and safety, this could give strategic advantages to competitors or even threaten flight safety.
Then, the data leak could have financial consequences for Boeing. The loss of trust and reputation could lead to a reduction in sales and customer.
Finally, the data leak could have negative implications for cybersecurity in general. Gaining access to sensitive Boeing information could allow attackers to develop new techniques and tools for cyberattacks , with negative consequences for the security of the internet and digital systems.
Source: www.bleepingcomputer.com
