Security

Cyber-crime

UN's aviation agency confirms attack on recruitment database

Various data points compromised but no risk to flight security


The International Civil Aviation Organization (ICAO), the United Nations' aviation agency, has confirmed to The Register that a cyber crim did indeed steal 42,000 records from its recruitment database.

Yesterday, we reported claims from an atacker that they had illegally accessed tens of thousands of documents. In response to our questions, the agency confirmed the haul pertained to particulars collected between April 2016 and July last year.

"The compromised data includes recruitment-related information that applicants entered into our system, such as names, email addresses, dates of birth, and employment history," said an ICAO spokesperson. 

Notably, the organization's statement omits any mention of data points such as home addresses, marital statuses, genders, and educational backgrounds, which were all allegedly included, per the leaker's claims.

"The affected data does not include financial information, passwords, passport details, or any documents uploaded by applicants," the spokesperson added.

The ICAO went on to say that the theft took place on its recruitment system and that no other systems were accessed or affected, including those responsible for aviation safety or security operations.

Additional security measures were implemented in the immediate aftermath of the break-in and the ICAO is currently working to identify the individuals affected before sending direct breach notifications.

"ICAO takes the privacy and security of personal information extremely seriously. We will provide further updates as our investigation progresses," the spokesperson added.

Headquartered in Montreal, the ICAO is a part of the UN which manages and regulates global air navigation systems, ensuring the 193 countries it oversees collaborate effectively on aviation matters.

It facilitates the communication between states during the decision-making process for new and amended flight routes, for example.

The agency - as we know it now - was formed in 1947 but was preceded by the International Commission for Air Navigation (ICAN), which first assembled in 1903 and was formally established in the 1919 Paris Convention.

ICAN was responsible for developing the first radio callsigns used by aircraft in 1912. It was replaced by the temporary Provisional International Civil Aviation Organization (PICAO) in 1945, ushered in as part of the Convention on International Civil Aviation with a view to being replaced by a permanent body, the ICAO, after the convention was ratified by member countries.

Now, it has broad diplomatic responsibilities that span matters related to flight paths and accident investigations. It also oversees aviation efficiency systems and environmental protection measures, as well as implementing technical standards across all facets of the aviation industry. ®

Send us news
4 Comments

Turbulence at UN aviation agency as probe into potential data theft begins

Crime forum-dweller claims to have leaked 42,000 documents packed with personal info

I tried hard, but didn't fix all of cybersecurity, admits outgoing US National Cyber Director

In colossal surprise, ONCD boss Harry Coker says more work is needed

DEF CON's hacker-in-chief faces fortune in medical bills after paralyzing neck injury

Marc Rogers is 'lucky to be alive'

Datacus extractus: Harry Potter publisher breached without resorting to magic

PLUS: Allstate sued for allegedly tracking drivers; Dutch DDoS; More fake jobs from Pyongyang; and more

Feds sue Southwest for chronic delays, unrealistic schedules

Department of Transportation wants in on last-minute Biden administration action too

Infoseccer: Private security biz let guard down, exposed 120K+ files

Assist Security’s client list includes fashion icons, critical infrastructure orgs

Boeing going backwards as production’s slowing and woes keep flowing

No such problems at Airbus, which cruised at a high level and shipped almost two planes a day last year

SEC sues Elon Musk for allegedly screwing investors out of $150M before Twitter takeover

Plus: SpaceX rocket re-entries spark airline delays

Snyk appears to deploy 'malicious' packages targeting Cursor for unknown reason

Packages removed, vendor said to have apologized to AI code editor as onlookers say it could have been a test

Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug

This is what happens when you publish PoCs immediately, hm?

Nominet probes network intrusion linked to Ivanti zero-day exploit

Unauthorized activity detected, but no backdoors found

Europe coughs up €400 to punter after breaking its own GDPR data protection rules

PLUS: Data broker leak reveals extent of info trading; Hot new ransomware gang might be all AI, no bark; and more