The Everest ransomware group claimed responsibility for a significant cyberattack on Dublin Airport, exfiltrating the personal data of over 1.5 million passengers. The stolen information includes full names, flight details, frequent flyer information, baggage tag numbers, and other sensitive travel data. The group listed Dublin Airport as a victim on its leak site, password-protecting the data and demanding negotiations within six days to prevent public release. Irish authorities and the National Cyber Security Centre have launched investigations, while Dublin Airport faces the challenge of rebuilding its affected servers from scratch.
The attack highlights critical vulnerabilities in aviation infrastructure, particularly the reliance on centralized software platforms such as Collins Aerospace’s MUSE system. The incident has caused operational disruptions, forcing manual fallback procedures and resulting in significant delays and inconvenience for passengers. The Everest campaign underscores the urgent need for enhanced cybersecurity resilience across the aviation sector, as the breach not only threatens data privacy but also exposes the operational fragility of major airports.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Everest said the stolen Dublin Airport passenger data was being held in password-protected form as part of a double-extortion scheme and gave the airport six days to respond before public release. The demand was later reported as a $1 million payment tied to the data.
Irish authorities and the National Cyber Security Centre were reported to be investigating the claimed breach affecting Dublin Airport. The airport was also said to be rebuilding servers from scratch, with no recovery timeline disclosed.
Reporting on the incident tied the Dublin Airport compromise to broader disruption affecting the aviation sector following issues involving Collins Aerospace systems, which had forced some European airports into manual operations. This framed the airport breach as part of a larger operational and cybersecurity impact chain.
On its leak site, the Everest ransomware group claimed it had breached Dublin Airport and stolen 1,533,900 passenger records. The group said the data included names, flight details, frequent-flyer information, travel status indicators, and baggage tag data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcethecyberthrone.in
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.