Latest / Tech Talks With Kinsoft / Aviation Under Siege: Qantas and Hawaiian Cyberattacks
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. We're here
- 0:02to unpack some recent, really critical information
- 0:04from a stack of sources, stuff that impacts you,
- 0:07the listener, especially if you're tracking how
- 0:10tech shapes our world, and importantly, its security.
- 0:14Today, we're looking at something that's, well,
- 0:16it's been all over the headlines, and frankly,
- 0:18sending a few shivers through the travel industry.
- 0:20Yeah, major cyber attacks targeting airlines.
- 0:23Exactly. We've got some fascinating, maybe a
- 0:25bit concerning insights from reports about Qantas
- 0:28and Hawaiian Airlines. That's right. And our
- 0:32goal today is really to cut through the noise,
- 0:33look at the specifics of what happened in these
- 0:36incidents. OK. And understand why they signal
- 0:39a pretty significant step up in cybersecurity
- 0:41threats for the whole aviation sector. We'll
- 0:44look at, you know, not just what happened, but
- 0:46the bigger picture. What does this mean for how
- 0:48organizations, especially airlines, need to adapt?
- 0:51Because the landscape is changing fast. Right.
- 0:53So let's start with Qantas. That breach you mentioned
- 0:56from July 2nd, they called it significant. What
- 0:58exactly got exposed there? And how does an airline
- 1:01that big even get hit like that? Yeah, it was
- 1:03serious. Qantas confirmed it, called it significant.
- 1:05Like you said, it affected up to six million
- 1:08customers. Six million. Wow. Huge number. The
- 1:12compromised data. It included personal details,
- 1:15names, emails, phone numbers, dates of birth,
- 1:17even frequent flyer numbers. Okay. Now, crucially,
- 1:21Qantas was quick to point out that no financial
- 1:23data or passport info was taken. That's obviously
- 1:27a relief. But still, the sheer amount of personal
- 1:30information, PII as it's called. Makes this one
- 1:34of the most serious breaches in Australian aviation
- 1:36history. I mean, for a customer, just knowing
- 1:39your basic details and travel history might be
- 1:41out there, even without the financial stuff,
- 1:43that's really unsettling. Yeah, absolutely. And
- 1:45how did it happen? Was it like a direct assault
- 1:47on their main systems? Yeah. Or something? Well,
- 1:50something sneakier. Well, this is what's really
- 1:52eye -opening. The breach didn't actually happen
- 1:54through Qantas' main internal systems. No, it
- 1:57came through a third -party platform, one used
- 1:59by their call center. Ah, the vendor risk. Exactly.
- 2:03It highlights this persistent, maybe underestimated
- 2:06vulnerability relying on outside vendors. And
- 2:10in aviation, it's not just about any vendor.
- 2:12The supply chain has this unique fragility. You
- 2:15know, imagine a tiny software patch in some third
- 2:18party flight planning tool. And that one vulnerability
- 2:22could potentially ground an entire fleet. That's
- 2:25the kind of risk we're looking at now. So what
- 2:28did Qantas do? Well, they acted fast. Shut down
- 2:31the affected systems. Started notifying customers.
- 2:34They even put in place extra ID checks for frequent
- 2:37flyer account changes. Right. And then there
- 2:39was this other twist, wasn't there? Yeah. Just
- 2:40last week, Conda said they were contacted by
- 2:42someone claiming responsibility. A potential
- 2:45cyber criminal. That seems unusual. It is. unusual
- 2:48definitely adds another layer to their response
- 2:50the source material doesn't spell out if they
- 2:52demanded ransom or what the contact was about
- 2:55exactly but you know direct contact like that
- 2:57it could be for ransom could be for publicity
- 2:59maybe even to prove they can do it for future
- 3:01extortion it's a bold move anyway shows the attackers
- 3:04want to be seen and qantas is working with the
- 3:06police on that yeah the australian federal police
- 3:09the afp they're trying to verify the contact
- 3:11and help with the ongoing investigation okay
- 3:13and The public reaction, the CEO apologized,
- 3:16right? Yes. Vanessa Hudson issued a public apology,
- 3:19emphasizing taking it seriously, aiming for transparency.
- 3:23Understandably, it's caused a lot of stress for.
- 3:26millions of customers. I bet. They've apparently
- 3:28had over 5 ,000 customer inquiries already. And
- 3:32there's even murmurs of a potential class action
- 3:34lawsuit. People are drawing parallels to other
- 3:37big Australian breaches like Optus and Medibang.
- 3:41Right, where there were significant compensation
- 3:43claims. Exactly. So it's clear this isn't just
- 3:45some IT glitch. It's a massive issue of customer
- 3:49trust. And it's unsettling because, as you said,
- 3:51Qantas wasn't alone. Just days before that news
- 3:54broke, there was another Another big warning,
- 3:56this time from the FBI. Yeah, that's right. Naming
- 3:58Hawaiian Airlines specifically, talking about
- 4:01a coordinated cybercrime campaign. How does that
- 4:04fit in? It fits perfectly, unfortunately. It
- 4:07shows a clear pattern, a worrying trend of escalating
- 4:12ransomware attacks hitting airlines globally.
- 4:14Now, Orion Airlines didn't confirm they were
- 4:16actually breached successfully, but the FBI advisory
- 4:20was crystal clear. They described the attackers
- 4:23as persistent and technically advanced. This
- 4:26isn't just random hacking. It feels like a strategic,
- 4:29coordinated effort. They're looking for weak
- 4:31spots across the whole aviation ecosystem. What
- 4:34kind of weak spots? Often things like gaps in
- 4:37employee training, maybe outdated I .T. systems
- 4:39and crucially, those third party access controls
- 4:42we just talked about with Qantas. It really drives
- 4:45home that this isn't just bad luck for one airline.
- 4:47It's part of a bigger, evolving threat. And when
- 4:50the FBI says sophisticated methods. What are
- 4:53we actually talking about? It's not just phishing
- 4:55emails anymore, is it? Oh, far from it. The FBI
- 4:58warning detailed tactics that show a real shift
- 5:00towards, well, psychological manipulation and
- 5:03pretty advanced deception. They mentioned the
- 5:05ransomware group using social engineering tactics,
- 5:08basically tricking people, but also deep fake
- 5:11technology and even insider impersonation to
- 5:14try and get into sensitive systems. Deep fakes.
- 5:17Wow. Yeah. And connecting this back, it really
- 5:19confirms that even, say, regional carriers like
- 5:22Hawaii and airlines aren't safe anymore. They're
- 5:24not off the radar. The threat landscape is just
- 5:26expanding so fast. No airline, big or small,
- 5:30seems immune. You mentioned a ransomware group.
- 5:33Our sources suggest a group called Scattered
- 5:35Spider might be behind at least one of these,
- 5:38maybe Qantas, given the methods. Who are they?
- 5:40What makes them different? Oh, Scattered Spider.
- 5:43Yes. They really burst onto the scene, gained
- 5:45notoriety in 2023. They hit some big names in
- 5:48hospitality and entertainment, MGM resorts, Caesars
- 5:51Entertainment. I remember that. Right. And their
- 5:53defining trait is, well, they're unconventional
- 5:56and deceptive methods. They're not primarily
- 5:58trying to break through firewalls in the classic
- 6:01set. So what are they doing? They're masters
- 6:02of social engineering. They use things like SIM
- 6:05swapping, getting control of someone's phone
- 6:07number to intercept texts or calls, and help
- 6:11desk impersonation pretending to be IT support
- 6:13to trick employees into giving up their passwords
- 6:16or credentials. So it's less about the tech vulnerabilities
- 6:18and more about exploiting people, weaponizing
- 6:21trust itself. Precisely. They go after the human
- 6:24element, the weakest link. So traditional defenses
- 6:27like firewalls, they're becoming less effective
- 6:30against groups like this that's concerning and
- 6:32it gets worse what's truly unsettling is how
- 6:35they're using deepfake video calls. You mentioned
- 6:38that. How does that work? Imagine getting a video
- 6:39call. It looks and sounds like your CEO or maybe
- 6:42the head of IT asking you to do something urgent.
- 6:45Transfer funds, grant access. But it's not them.
- 6:48Exactly. It's a sophisticated deepfake. They
- 6:51also do these multi -factor authentication fatigue
- 6:54attacks or MFA fatigue. What's that? They basically
- 6:58spam an employee's phone with login approval
- 7:00requests over and over again until the employee
- 7:03just hits approve by mistake. just to make the
- 7:06notification stop. I could see how that would
- 7:08work. Right. Combine that with stolen credentials,
- 7:11maybe bought off the dark web or phished earlier,
- 7:13and they can get initial access pretty quickly.
- 7:15And it's incredibly hard to spot. They really
- 7:18prioritize stealth and psychological tricks over
- 7:20brute force hacking. It's a tough defense challenge
- 7:23when your own people are, you know, unknowingly
- 7:26helping the attackers. That shift towards the
- 7:28psychological targeting people. It sounds incredibly
- 7:33difficult to defend against. So what does all
- 7:34this mean for the wider aviation industry, especially
- 7:37with groups like Scattered Spider out there?
- 7:39Well, these incidents, Qantas, the FBI warning,
- 7:42they're really symptoms of a much bigger systemic
- 7:46issue. Airlines are just such high value targets.
- 7:49Why specifically airlines? Several reasons. First,
- 7:52they handle massive amounts of personal data,
- 7:54PII, from millions of people. Right. Names, travel
- 7:57plans. More than that. Travel patterns, meal
- 8:00preferences, loyalty points, sometimes even medical
- 8:02needs. That data is gold for identity thieves,
- 8:06for crafting targeted phishing attacks, even
- 8:08for intelligence gathering by other bad actors.
- 8:11Second, airlines often rely heavily on legacy
- 8:13systems. Think about reservation platforms, flight
- 8:16ops software, maybe even air traffic control
- 8:18interfaces that could be decades old. Running
- 8:21on old code. Potentially. Yeah. And updating
- 8:23them isn't simple. It's not just a software patch.
- 8:26It's often a massive, multi -year, multi -million
- 8:29dollar project. You have to plan meticulously
- 8:32to avoid disrupting flights. Yeah, you can't
- 8:34just turn it off and on again. Exactly. So it
- 8:37leaves these systems hard to secure against modern,
- 8:39agile threats without causing chaos. And third,
- 8:43like we saw so clearly with Qantas, they use
- 8:45tons of third -party vendors. This creates this
- 8:48huge digital supply chain of vulnerability in
- 8:51one small vendor. could be the entry point for
- 8:53attackers to get into the airline's main network.
- 8:56It sounds like a perfect storm, really. Valuable
- 8:58data, complex old systems, tangled supply chains.
- 9:01It is. It's not just these vulnerabilities alone.
- 9:03It's how they all connect. Airlines are like
- 9:06these digital cities in the sky. Everything from
- 9:09baggage handling to navigation relies on these
- 9:12complex, sometimes ancient digital links. A breach
- 9:16somewhere isn't just a data leak. It can ripple
- 9:18through operations, safety. even national infrastructure.
- 9:23That paints a pretty stark picture and does it
- 9:25vary globally. Are airlines in some regions better
- 9:27prepared than others? Absolutely, there are differences.
- 9:30The sources point to inconsistent cybersecurity
- 9:33regulations and enforcement across regions like
- 9:36Southeast Asia, EMEA, Latin America. How so?
- 9:39Well, you have the EU's GDPR, which is quite
- 9:42strict. Clear rules, big potential fines. But
- 9:45other regions say Thailand with its PDPA or Brazil
- 9:48with LGPD. They're improving data protection,
- 9:51definitely, but they often still lack aviation
- 9:53-specific enforcement mechanisms. So the rules
- 9:56aren't tailored? Not always, or the enforcement
- 9:58isn't as robust. And the problem is a breach
- 10:01often hits passengers from many different countries,
- 10:03so the airline has to navigate this patchwork
- 10:05of laws. GDPR might demand quick, strict action.
- 10:09But if an airline operates mainly where data
- 10:11laws are newer or less mature, they might face
- 10:13fewer immediate penalties or have less clear
- 10:16obligations. This creates different incentives
- 10:19for investing in security and how they respond
- 10:21to breaches globally. It leads to fragmented
- 10:24security levels and a confusing legal mess when
- 10:27things go wrong. OK, so given this escalating
- 10:30threat, these sophisticated tactics from groups
- 10:32like Scattered Spider. What's the urgent advice
- 10:36for airlines? How do they protect themselves
- 10:38and us, their customers, from what sounds almost
- 10:41inevitable? Well, cybersecurity experts are really
- 10:44urging immediate proactive steps. Top of the
- 10:46list is investing in things like managed detection
- 10:49and response or MDR services. MDR. What's that?
- 10:52Practically. Think of it like having an expert
- 10:54security team watching your digital footprint
- 10:5624 -7. They're constantly looking for threats,
- 10:59ready to jump in the moment something suspicious
- 11:01pops up, not just reacting after you know you've
- 11:03been breached. Okay, proactive monitoring. Exactly.
- 11:06Also, doing regular thorough security audits,
- 11:10finding and fixing vulnerabilities before the
- 11:12attackers do, and crucially, implementing really
- 11:15strict vendor risk assessments, locking down
- 11:18those third party doors. Makes sense. Because
- 11:20the cost of not doing this, it could be truly
- 11:22catastrophic. We're talking grounded fleets,
- 11:25reputation shattered for years, massive customer
- 11:29distrust, which for an airline, that can be fatal.
- 11:33Yeah, it's clearly not just an IT department
- 11:35problem anymore, is it? It's fundamental to operations,
- 11:38to safety, to the bottom line. I mean, imagine
- 11:40your flights delayed for hours, not because of
- 11:43weather, but because the airline's booking system
- 11:44is locked down by ransomware. That's the real
- 11:47world impact. So these Qantas and Hawaiian Airlines
- 11:50incidents, they really are a wake up call, aren't
- 11:52they, for the whole global aviation industry?
- 11:54Absolutely. Whether it's through those vulnerable
- 11:55third party systems or this incredibly clever
- 11:58social engineering, the message seems undeniable.
- 12:01The threat is real and it's evolving fast. And
- 12:04it raises a big question really for all businesses,
- 12:06not just airlines. How proactive are you in preparing
- 12:10for threats like Scattered Spider? It just underscores
- 12:14this critical need for organizations to see cybersecurity
- 12:17not as some IT cost center, but as a core operational
- 12:22priority. Meaning what specifically? Meaning
- 12:25investing in ongoing employee education, having
- 12:27real -time threat detection like MDR, and really
- 12:30robust controls over third -party access. Because
- 12:33this isn't just an aviation issue. The supply
- 12:36chain weaknesses we're seeing here, that's a
- 12:38blueprint for attacks on almost any industry
- 12:40that relies on complex digital connections. It
- 12:43is a complex landscape, no doubt. But hopefully,
- 12:46understanding these trends like we've tried to
- 12:47do today is that first step towards building
- 12:50stronger defenses. And that brings us to the
- 12:52end of Tech Talks with Kinsoft for today. We
- 12:55hope this exploration into aviation cybersecurity
- 12:57has given you some valuable insights, maybe help
- 12:59connect some dots on this really critical topic.
- 13:02Yeah. And if these kinds of discussions make
- 13:04you think about your own organization's security
- 13:06posture, your IT needs, whether you're in aviation
- 13:09or any sector facing these digital challenges,
- 13:12we really encourage you to visit www .kinsoft
- 13:14.com .au. That's www .kinsoft .com .au. Their
- 13:20team is ready to help you navigate these complex
- 13:22issues and work towards securing your digital
- 13:24future. Great advice. Thanks everyone for tuning
- 13:26in, and we'll catch you next time on Tech Talks
- 13:28with Kinsoft.