American Airlines subsidiary Envoy confirms Oracle data theft attack

American Airlines subsidiary Envoy Airlines has confirmed a data breach involving Oracle, where attackers stole sensitive information. The incident highlights the growing threat of cyberattacks targeting airline subsidiaries and their critical data infrastructure. Envoy Airlines reported the breach after discovering unauthorized access to their Oracle systems, which store vital customer and operational data. This attack underscores the importance of robust cybersecurity measures in the aviation industry, especially for subsidiaries handling large volumes of sensitive data. Oracle, a major cloud and database service provider, has been targeted in various cyber incidents, emphasizing the need for enhanced security protocols. The breach at Envoy Airlines serves as a cautionary tale for other companies relying on third-party cloud services, urging them to strengthen their defenses against sophisticated cyber threats. Organizations are advised to conduct thorough security audits, implement multi-factor authentication, and monitor network activities closely to prevent similar data thefts. This event also raises awareness about the potential risks associated with supply chain attacks, where attackers exploit vulnerabilities in interconnected systems. As cybercriminals continue to evolve their tactics, companies must prioritize cybersecurity investments to protect their data and maintain customer trust. The Envoy Airlines Oracle data theft incident is a stark reminder of the persistent cyber threats facing the aviation sector and the critical need for proactive defense strategies.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Fri, 17 Oct 2025 19:15:14 +0000


Cyber News related to American Airlines subsidiary Envoy confirms Oracle data theft attack

American Airlines subsidiary Envoy confirms Oracle data theft attack - American Airlines subsidiary Envoy Airlines has confirmed a data breach involving Oracle, where attackers stole sensitive information. The incident highlights the growing threat of cyberattacks targeting airline subsidiaries and their critical data ...
4 months ago Bleepingcomputer.com
How to perform a proof of concept for automated discovery using Amazon Macie | AWS Security Blog - After reviewing the managed data identifiers provided by Macie and creating the custom data identifiers needed for your POC, it’s time to stage data sets that will help demonstrate the capabilities of these identifiers and better understand how ...
1 year ago Aws.amazon.com
American Airlines pilot union hit by ransomware attack - Allied Pilots Association, a labor union representing 15,000 American Airlines pilots, disclosed a ransomware attack that hit its systems on Monday. The APA union was founded in 1963 and is currently the largest independent pilots' trade union in the ...
2 years ago Bleepingcomputer.com LockBit Black Basta
Congressman Coming for Answers After No-Fly List Hack - U.S. Congressman Bennie Thompson is demanding answers from airlines and the federal government after a "massive hack" of the no-fly list. The congressman sent a letter to the airlines and the Department of Homeland Security asking for an explanation ...
3 years ago Therecord.media
Hawaiian Airlines discloses cyberattack, flights not affected - Hawaiian Airlines also hired external cybersecurity experts to asses the attack's impact and help restore affected systems. The airline stated in a statement issued on Thursday morning that the incident didn't affect flight safety and has already ...
8 months ago Bleepingcomputer.com
31 Alarming Identity Theft Statistics for 2024 - Identity theft is a prevalent issue that affects millions of people annually. Although the numbers are startling, we've selected the 31 most concerning identity theft statistics to help you understand how to secure your identity. In 2022, the FTC ...
2 years ago Pandasecurity.com
How to Keep Cyberattacks From Taking Off - COMMENTARY. Over the last three years, the global aviation industry has been left reeling by a post-pandemic sucker punch that hit the sector with over $185 billion in losses. Once a bastion of American prosperity, airlines were forced into survival ...
2 years ago Darkreading.com
CVE-2016-0635 - Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, ...
6 years ago
CVE-2020-15127 - In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's ...
5 years ago
CVE-2021-32783 - Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the ...
4 years ago
CVE-2021-32779 - Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with an ...
3 years ago
American Family Insurance confirms cyberattack is behind IT outages - Insurance giant American Family Insurance has confirmed it suffered a cyberattack and shut down portions of its IT systems after customers reported website outages all week. American Family Insurance is an insurance company focusing on commercial and ...
2 years ago Bleepingcomputer.com
The Latest Identity Theft Methods: Essential Protection Strategies Revealed - Identity theft has evolved far beyond the days of stolen mail and dumpster diving. Today's identity thieves employ sophisticated techniques, including account takeovers and government benefit fraud, making it essential for you to stay vigilant to ...
2 years ago Hackread.com
Yamaha Motor confirms ransomware attack on Philippines subsidiary - Yamaha Motor's Philippines motorcycle manufacturing subsidiary was hit by a ransomware attack last month, resulting in the theft and leak of some employees' personal information. "One of the servers managed by [.] motorcycle manufacturing and sales ...
2 years ago Bleepingcomputer.com Inc ransom
CVE-2024-45806 - Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or other malicious actions within the mesh. This ...
1 year ago
Collins Aerospace working on restoring software for airlines hit by cyber attack - Collins Aerospace, a major player in the aerospace and defense sector, is actively engaged in restoring software systems for airlines affected by a recent cyber attack. The incident disrupted critical airline operations, highlighting the increasing ...
5 months ago Reuters.com
Oracle privately confirms Cloud breach to customers - This comes after a threat actor (known as rose87168) put up for sale 6 million data records on BreachForums on March 20 and released multiple text files containing a sample database, LDAP information, and a list of the companies as proof that the ...
11 months ago Bleepingcomputer.com
Oracle privately confirms Cloud breach to customers - This comes after a threat actor (known as rose87168) put up for sale 6 million data records on BreachForums on March 20 and released multiple text files containing a sample database, LDAP information, and a list of the companies as proof that the ...
11 months ago Bleepingcomputer.com
Unmasking Identity Theft: Detection and Mitigation Strategies - In an increasingly digital world, the threat of identity theft looms large, making it imperative for individuals to be proactive in detecting potential breaches and implementing effective mitigation measures. This article delves into key strategies ...
2 years ago Cybersecurity-insiders.com
CVE-2025-64763 - Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it accepts client data before issuing a 2xx response and forwards that ...
3 months ago
CVE-2025-24030 - Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on ...
1 year ago Tenable.com
CVE-2022-29224 - Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a ...
3 years ago
Oracle’s First Security Update for 2023 Includes 327 New Patches - Oracle has released its first security update of 2023, delivering 327 new security fixes and patching a range of critical vulnerabilities. This update covers products spanning across Oracle’s Cloud portfolio, Fusion Middleware, Hyperion, E-Business ...
3 years ago Securityweek.com
American Intellectual Property Theft a $600 Billion Dollar Issue - American Intellectual Property theft is costing the domestic economy as much as $600 billion per year, as reported by the Associated Press, and it appears lawmakers and watchdogs have taken note. Understanding the events that have precipitated the ...
2 years ago Securityzap.com
Oracle says "obsolete servers" hacked, denies cloud breach - BleepingComputer has also separately confirmed with multiple Oracle customers that samples of the leaked data (including associated LDAP display names, email addresses, given names, and other identifying information) received from the threat actor ...
11 months ago Bleepingcomputer.com