Bangkok Airways confirms LockBit ransomware has leaked 200GB+ of data including passenger details; LockBit has also published stolen data of Ethiopian Airlines
Ionut Ilascu / BleepingComputer :
Context & Ripple Effects
This is the second airline passenger-data crisis of 2021 in the coverage: months earlier, [[a:966603|Air India disclosed that 4.5 million passengers' names, passport details, and credit card data were stolen]]. Bangkok Airways' case is different in kind — LockBit moved from theft to publication, dumping 200GB+ on its leak site and doing the same to Ethiopian Airlines.
The pattern hardens later in the corpus: LockBit hit Boeing in October 2023 and, when the company refused to pay, posted ~43GB — Boeing confirmed the gang attempted a $200M extortion. Publication after non-payment is the enforcement mechanism, not an outlier.
First-order effects
- Bangkok Airways passengers whose details are in the 200GB+ dump face exposure of personal data with no further control by the airline — the breach has moved from private incident to public record.
- Ethiopian Airlines joins the leak site alongside Bangkok Airways, meaning two carriers' negotiations with LockBit have ended in publication rather than payment.
Second-order effects
- Boeing's refusal-and-leak outcome becomes the reference point for other targeted organizations weighing whether paying prevents publication — the corpus suggests it may not, since Boeing's data was posted anyway after the demand.
- Airlines and their IT suppliers face renewed pressure on third-party and legacy system security, echoing the MOVEit episode where British Airways warned staff their data was stolen via a supplier's tool rather than its own.
Third-order effects
- Aviation is emerging as a standing target class for ransomware-as-a-service crews — Air India, Bangkok Airways, Ethiopian Airlines, and Boeing across the corpus — pushing carriers toward assuming breach-and-leak rather than prevention-only postures.
- The model's durability is not guaranteed: experts cited in the coverage report LockBit weakening, and the later defacement of LockBit's affiliate panels exposed victim chats and tens of thousands of BTC addresses, turning the gang's own infrastructure into leaked data.
The trend: Ransomware-as-a-service gangs are making leak-site publication the default penalty for non-payment, and airlines have become one of their most reliable victim categories.