Massive Cyberattack on Russia’s Aeroflot Disrupts Flights
On July 28, 2025, Russia’s largest airline, Aeroflot, faced a significant cyberattack that crippled its operations, leading to the cancellation of over 100 flights and widespread disruption at Moscow’s Sheremetyevo Airport. The attack, claimed by pro-Ukrainian hacking groups Silent Crow and Belarusian Cyberpartisans, marks one of the most severe cyberattacks on Russian infrastructure since the onset of the Russia-Ukraine conflict in February 2022. This article delves into the details of the cyberattack, its impact on Aeroflot and passengers, the motives behind the attack, and the broader implications for cybersecurity in geopolitically sensitive industries.
Details of the Cyberattack
The cyberattack targeted Aeroflot’s information technology systems, resulting in a massive outage that grounded flights across Russia and affected international routes to destinations like Minsk, Belarus, and Yerevan, Armenia. According to reports, the hackers claimed to have penetrated Aeroflot’s network over a year-long operation, destroying approximately 7,000 physical and virtual servers and accessing terabytes of sensitive data, including flight records, employee information, and customer details.
A statement from Silent Crow, as reported by Reuters, declared, “Glory to Ukraine! Long live Belarus!” emphasizing the attack’s political motivations linked to Russia’s ongoing war in Ukraine. The hackers further claimed to have taken control of the personal computers of Aeroflot’s senior managers and threatened to leak the personal data of all Russians who have ever flown with the airline, along with intercepted staff emails and conversations. Screenshots shared by the hackers purportedly showed access to Aeroflot’s internal systems, including active directories and file shares, though no definitive evidence has been publicly verified.
The Belarusian Cyberpartisans, in a statement on their website, stated, “We are helping Ukrainians in their fight with the occupier, carrying out a cyber strike on Aeroflot and paralyzing the largest airline in Russia.” This group, known for previous cyberattacks on Belarusian and Russian targets, described the operation as a “crushing blow” aimed at disrupting Russia’s critical infrastructure.
The hacker collective known as “Silent Crow,” in collaboration with the Belarusian group Cyberpartisans BY, claimed responsibility for the cyberattack through a Telegram post. They announced:
“We proclaim the successful conclusion of an extensive and long-term operation, during which the internal IT framework of Aeroflot was entirely compromised and destroyed. Glory to Ukraine! Long live Belarus!”
Russia’s state airline Aeroflot has just cancelled around 50 flights, citing a disruption to its information systems.
— KyivPost (@KyivPost) July 28, 2025
Hacker groups Silent Crow and Cyber Partisans BY claim responsibility, saying the hit was a year in the making. pic.twitter.com/qVxxJ75EJr
Scope and Depth of the Breach
Hackers asserted that they had infiltrated Aeroflot’s core systems for an entire year, meticulously escalating their access. They claim to have destroyed up to 7,000 servers and extracted between 12–20 terabytes of sensitive data—including customer records, internal correspondence, recordings of phone calls, surveillance material of employees, and other confidential files. They threatened to publish the compromised data unless their demands were met:
“The personal data of all Russians who have ever traveled with Aeroflot has now embarked on a journey – though without luggage and heading to the same destination,” the group quipped grimly in a now-viral message.
Aeroflot has not confirmed these numbers but acknowledged that its critical IT infrastructure had suffered a catastrophic failure caused by a cyberattack.
Impact on Aeroflot and Passengers
Aeroflot, one of the top 20 airlines globally by passenger numbers, with 55.3 million passengers in 2024, was severely impacted by the attack. The airline’s website was temporarily unavailable, displaying an error message about restricted access, and its call center and mobile app were also down, leaving passengers stranded with little information. Social media posts on platforms like VK captured the frustration of affected travelers. One passenger, Malena Ashi, wrote, “I’ve been sitting at Volgograd airport since 3:30!!!!! The flight has been rescheduled for the third time!!!!!! This time it was rescheduled for approximately 14:50, and it was supposed to depart at 5:00!!!” Another passenger, Yulia Pakhota, complained, “The call centre is unavailable, the website is unavailable, the app is unavailable.”
Aeroflot confirmed the cancellation of 54 round-trip flights, though some sources reported over 100 cancellations, with an additional 10 flights delayed. The airline issued a statement on Telegram, saying, “There was a failure in the airline’s information systems. Service interruptions are possible. Currently, a team of specialists is working to minimize the risks of fulfilling the production flight plan and quickly restoring the normal operation of services. The airline apologizes for the inconvenience caused.” Affected passengers were offered refunds or the option to rebook within 10 days.
The disruption was particularly acute at Sheremetyevo Airport, Aeroflot’s primary hub, where departure boards turned red with cancellations during a peak holiday period. The outage also impacted Aeroflot’s subsidiaries, Rossiya and Pobeda, further amplifying the chaos. Images shared on social media depicted crowded terminals and frustrated passengers, highlighting the scale of the disruption.
In the words of Andrei Litvinov, a former Aeroflot pilot and aviation analyst:
“This is a significant catastrophe. Flight delays can be managed, but these are substantial losses for a state-owned entity. If all correspondence and corporate data are compromised, it could have very long-lasting repercussions… First the drones, and now they are undermining the situation from within”.
National and Political Reaction
The cyberattack immediately drew widespread concern and condemnation from Russian authorities. The Kremlin labeled it “concerning” and “a crucial alert for the country”, while the Prosecutor General’s Office and the Federal Security Service (FSB) swiftly launched a criminal investigation.
Russian lawmakers offered a stark warning, with Anton Gorelkin stating:
“We must remember that the conflict against our nation is being fought on all fronts, including the digital arena. I do not discount the possibility that the ‘hacktivists’ who have claimed responsibility for this event are operating on behalf of hostile nations”.
National and Political Reaction
The cyberattack immediately drew widespread concern and condemnation from Russian authorities. The Kremlin labeled it “concerning” and “a crucial alert for the country”, while the Prosecutor General’s Office and the Federal Security Service (FSB) swiftly launched a criminal investigation.
Russian lawmakers offered a stark warning, with Anton Gorelkin stating:
“We must remember that the conflict against our nation is being fought on all fronts, including the digital arena. I do not discount the possibility that the ‘hacktivists’ who have claimed responsibility for this event are operating on behalf of hostile nations”.
Another prominent parliamentarian, Anton Nemkin, emphasized the need for accountability, urging not only to find the hackers but also to root out those responsible for “systemic vulnerabilities in security measures”.
Motives and Context
The cyberattack on Aeroflot appears to be a politically motivated act tied to the ongoing Russia-Ukraine conflict. Silent Crow and Belarusian Cyberpartisans have a history of targeting Russian and Belarusian entities in support of Ukraine. Silent Crow, for instance, has claimed responsibility for attacks on a Russian real estate database, a state telecom company, a large insurance firm, and the Moscow government’s IT department earlier in 2025. The Belarusian Cyberpartisans previously infiltrated Belarus’ KGB security agency network in April 2024, demonstrating their capability for high-profile cyberattacks.
Rafe Pilling, director of threat intelligence at Sophos, commented on the attack’s nature, stating, “It appears to be a sort of a politically motivated hacktivist event from two groups opposed to Russia. I get the impression that their objective is not a cybercrime ransomware attack. It is probably more of a disruption protest.” Unlike ransomware attacks, which typically seek financial gain, this incident aimed to disrupt operations and potentially expose sensitive data as a form of protest against Russia’s actions in Ukraine.
The timing of the attack, during a peak holiday period, maximized its impact on Russian travelers and underscored the hackers’ intent to cause widespread disruption. Since Russia’s invasion of Ukraine in February 2022, flight disruptions in Russia have become more common, often due to drone attacks or temporary airport closures. However, this cyberattack stands out for its scale and the reported depth of network penetration.
Broader Implications for Cybersecurity
The Aeroflot cyberattack highlights the growing threat of hacktivism in geopolitically charged conflicts. As critical infrastructure like airlines becomes increasingly digitized, vulnerabilities in IT systems can lead to significant real-world consequences. The reported destruction of 7,000 servers and the potential leak of 20 terabytes of data, including personal information of millions of passengers, raise serious concerns about data privacy and security.
This incident also underscores the challenges faced by large organizations in securing their networks against sophisticated, long-term cyberattacks. The hackers’ claim of a year-long operation suggests they exploited multiple vulnerabilities to gain deep access to Aeroflot’s systems. This could prompt Russian companies and government agencies to reassess their cybersecurity protocols, particularly for critical infrastructure.
For the global aviation industry, the Aeroflot attack serves as a warning. Airlines worldwide rely on interconnected IT systems for ticketing, scheduling, and operations, making them prime targets for cyberattacks. The disruption caused by this incident may lead to increased investment in cybersecurity measures and international cooperation to combat hacktivism and cybercrime.
Looking Ahead
At present, Aeroflot’s technical teams are striving to restore operations, but with thousands affected and the scale of the intrusion still being determined, a swift resolution remains uncertain. The Russian government has promised a thorough investigation.
As the digital front of the Russia-Ukraine conflict intensifies, the cyberattack on Aeroflot stands as a stark reminder of vulnerability in an interconnected world.
Conclusion
The cyberattack on Aeroflot by pro-Ukrainian hacking groups Silent Crow and Belarusian Cyberpartisans represents a significant escalation in the digital warfare accompanying the Russia-Ukraine conflict. By targeting Russia’s largest airline, the hackers disrupted travel for thousands of passengers and exposed potential weaknesses in Aeroflot’s cybersecurity infrastructure. The Russian government’s response, including a criminal investigation and public statements from officials, reflects the seriousness of the incident. As the hackers threaten to leak sensitive data, the fallout from this attack could have lasting implications for Aeroflot, its passengers, and Russia’s broader cybersecurity landscape.
The incident serves as a reminder of the evolving nature of cyber threats, particularly in times of geopolitical tension. For tech enthusiasts and industry professionals, this event underscores the importance of robust cybersecurity measures to protect critical infrastructure from politically motivated attacks. As investigations continue, the world will be watching to see how Russia responds and whether the hackers follow through on their threats to release stolen data.
For the latest updates, visit our tech blogs.
Last updated on July 29, 2025 at 3:09 am
