/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Boeing confirms that LockBit attempted to extort a $200M ransom in October 2023; the company reportedly didn't pay any ransom after ~43GB of its data was posted

AJ Vicens / CyberScoop :

CyberScoop AJ Vicens

Context & Ripple Effects

Boeing’s confirmation fills in the financial scale behind its earlier investigation into a cyber incident affecting its parts and distribution business, which began after LockBit claimed it had taken Boeing data.

The disclosure also corroborates the subsequent publication of Boeing data by LockBit, turning an initially disputed attack claim into a documented example of data-theft extortion.

First-order effects

  • Boeing has publicly established that the attempted October 2023 extortion sought $200 million and that it reportedly did not pay; roughly 43GB of data was nevertheless posted.
  • LockBit’s Boeing operation is now tied to a confirmed victim and a disclosed demand, rather than only the group’s public claims.

Second-order effects

  • For Boeing, the incident’s cost center shifts from the ransom decision to assessing and managing the consequences of data already exposed.
  • Other targeted organizations face a clearer reminder that refusing payment may not prevent publication: LockBit had previously leaked data following attacks on other aviation companies, including Bangkok Airways.

Third-order effects

  • The case reinforces the shift from ransomware as an availability attack to extortion centered on stolen data, where restoration of systems alone does not end the incident.
  • If prominent victims continue to disclose nonpayment after leaks, attackers may face pressure to demonstrate the value of their stolen data, while defenders will place more weight on limiting data access and exfiltration.

The trend: Ransomware groups are increasingly using data publication as independent leverage, making breach containment and disclosure consequences central to incident response.

Discussion

  • @quinnypig Corey Quinn on x
    Oh, they forgot to lock down the digital doors and windows too?
  • @shah_sheikh Shah Sheikh on x
    Boeing confirms attempted $200 million ransomware extortion attempt: That attempt was one of multiple “extremely large” ransom demands made by LockBit over the years, authorities said. The post Boeing confirms attempted $200 million ransomware... https://cyberscoop.com/... [image…