Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign

American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign

Posted on October 18, 2025October 18, 2025 By CWS

Envoy Air, an entirely owned subsidiary of American Airways, has confirmed it fell sufferer to a hacking marketing campaign exploiting vulnerabilities in Oracle’s E-Enterprise Suite (EBS).

The breach, first highlighted by the infamous Clop ransomware group, underscores the rising dangers dealing with enterprise software program within the aviation sector.

Clop, identified for high-profile extortion schemes just like the MOVEit Switch assaults, claimed duty final week, itemizing American Airways amongst over 60 organizations hit by unpatched flaws in Oracle EBS.

The group, which operates out of Russia-linked networks, has demanded ransoms in cryptocurrency, threatening to leak stolen information on its darkish website if unpaid.

Whereas Clop didn’t specify the precise vulnerabilities, safety researchers level to identified points in Oracle’s WebLogic Server and EBS modules, comparable to CVE-2023-21931, which permit distant code execution if not correctly secured.

Envoy’s admission got here swiftly after the claims surfaced, aiming to reassure stakeholders amid rising issues over aviation information safety.

Envoy Compromised

“We’re conscious of the incident involving Envoy’s Oracle E-Enterprise Suite software,” an Envoy spokesperson instructed Cybersecurity Information. “Upon studying of the matter, we instantly started an investigation and legislation enforcement was contacted”.

“We now have carried out a radical evaluate of the information at concern and have confirmed no delicate or buyer information was affected. A restricted quantity of enterprise info and business contact particulars could have been compromised.”

The spokesperson emphasised that passenger data, flight operations, and private identifiable info remained untouched, mitigating instant dangers to vacationers.

Nevertheless, the publicity of inner enterprise information may nonetheless pose challenges, together with potential phishing vectors or aggressive intelligence leaks for the regional provider, which operates over 150 plane and serves tens of millions of passengers yearly underneath the American Airways banner.

Consultants warn that this incident highlights systemic vulnerabilities in legacy enterprise programs. Oracle EBS, broadly used for HR, finance, and provide chain administration, has confronted criticism for gradual patching cycles.

Cybersecurity agency Mandiant famous in a current report that Clop’s techniques typically goal third-party software program to amplify attain, affecting not simply direct victims however total ecosystems.

As investigations proceed with federal authorities, together with the FBI’s cyber division, Envoy said it has carried out enhanced monitoring and up to date its Oracle programs. American Airways, whereas indirectly named in information leaks, has bolstered its subsidiary’s defenses in response.

This breach arrives amid a wave of aviation cyberattacks, from ransomware hitting airports to state-sponsored espionage. Trade leaders are urging sooner adoption of zero-trust architectures to safeguard essential infrastructure.

For now, Envoy passengers can fly with relative peace of thoughts, however the occasion serves as a stark reminder: in cybersecurity, one weak hyperlink can floor a whole operation.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Airlines, American, Campaign, Compromised, Envoy, Hacking, Oracle, Subsidiary

Post navigation

Previous Post: New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft
Next Post: Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode

Related Posts

Hackers Can Exploit Default ServiceNow AI Assistants Configurations to Launch Prompt Injection Attacks Hackers Can Exploit Default ServiceNow AI Assistants Configurations to Launch Prompt Injection Attacks Cyber Security News
New Red Teaming Tool RedTiger Attacking Gamers And Discord Accounts In The Wild New Red Teaming Tool RedTiger Attacking Gamers And Discord Accounts In The Wild Cyber Security News
VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection Cyber Security News
India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram, and Other Messaging Platforms India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram, and Other Messaging Platforms Cyber Security News
Countering Spear Phishing with Advanced Email Security Solutions Countering Spear Phishing with Advanced Email Security Solutions Cyber Security News
Vidar Stealer Bypassing Browser Security Via Direct Memory Injection to Steal Login Credentials Vidar Stealer Bypassing Browser Security Via Direct Memory Injection to Steal Login Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark