/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LockBit leaks ~50GB of data that the ransomware gang claims to have stolen from Boeing in October, after the company apparently refused to pay the ransom demand

Aerospace titan pores over data to see if dump is legit  —  The LockBit crew is claiming to have leaked all of the data …

The Register Jessica Lyons Hardcastle

Context & Ripple Effects

The alleged theft surfaced days after Boeing said it was investigating a cyber incident affecting its parts and distribution business, following LockBit's claim that it had taken a large volume of data. The claimed leak turns that earlier operationally focused incident into a potential data-exposure problem.

Later coverage said Boeing faced a $200 million extortion demand and did not pay after roughly 43GB was posted, lending context to the gang's use of publication as leverage rather than encryption alone.

First-order effects

  • Boeing must determine whether the released files are authentic and identify any affected employees, customers, suppliers, or operational information; the company had already linked the incident to its parts and distribution business.
  • LockBit can use the purported release to sustain pressure after an apparent refusal to pay, making public exposure—not merely system disruption—the immediate consequence of the attack.

Second-order effects

  • Organizations connected to Boeing may need to assess whether their information appears in the dump, expanding the response from internal recovery to third-party notification and exposure management.
  • The episode reinforces the playbook used against other aviation targets, including LockBit's publication of Bangkok Airways data, in which a victim's nonpayment does not end the extortion event.

Third-order effects

  • If data-leak extortion remains effective, ransomware preparedness will increasingly hinge on data classification, third-party access controls, and disclosure readiness alongside backup and restoration capabilities.
  • LockBit's alleged targeting of Boeing and an attack attributed to the group against ICBC point to a broader pressure on large, operationally critical organizations; the durability of that pattern depends on law-enforcement disruption and victims' ability to limit the value of stolen data.

The trend: Ransomware is shifting from a disruption-and-recovery problem toward a persistent data-extortion risk that reaches victims' partners and customers even when victims do not pay.

Discussion

  • @vxunderground @vxunderground on x
    Questions we have been asked: 1. Will Boeing pay Lockbit ransomware group? No. 2. Was Lockbit responsible for the ransomware attack against ICBC? Yes Source: Lockbit ransomware group administrative staff. They also want to explicitly state they are not Russian [image]
  • @malwrhunterteam @malwrhunterteam on x
    And here we go. After the second timer expired, now some files that should come from Boeing's systems are now published on the leak site of LockBit gang. [image]
  • @malwrhunterteam @malwrhunterteam on x
    I have no idea if LockBit gang really pwned Boeing with CVE-2023-4966 (CitrixBleed) as some people suggests, but Aviall / Boeing liked (and guess still like then) to decommission & patch their Citrix stuffs to for reasons like keeping the “environment healthy and compliant”... 🤷‍…
  • @alvierid Dominic Alvieri on x
    Boeing, you may want to take a look. @Boeing #LockBit [image]
  • r/UFOs r on reddit
    Boeing hacked by Lockbit