EgyptAir FunkSec Ransomware Targets National Carrier

Dec 2024 · Aviation sector

By Karim El Labban · ZERO|TOLERANCE

EgyptAir: FunkSec Ransomware Targets National Carrier

In December 2024, the AI-assisted ransomware group FunkSec claimed a breach of EgyptAir, Egypt's flag carrier airline.

FunkSec, notable for its integration of AI tools into malware development and operational workflows, listed stolen data on its dark web leak site including passenger manifests, employee records, and operational documents.

EgyptAir carries millions of passengers annually and holds extensive PII including passport numbers, travel itineraries, payment details, and frequent flyer records.

01

KEY FACTS

  • .What: FunkSec AI-assisted ransomware group attacked Egypt's flag carrier airline.
  • .Who: EgyptAir passengers, employees, and Star Alliance partner operations.
  • .Data Exposed: Passenger manifests, passport numbers, employee records, and payment data.
  • .Outcome: Data listed on FunkSec dark web leak site; no public penalty disclosed.
02

WHAT WAS EXPOSED

  • .Passenger Name Records (PNRs) containing full names, passport numbers, nationalities, travel itineraries
  • .Frequent flyer program data including membership tiers, accumulated miles, travel history
  • .Employee records including personnel files, salary information, national IDs
  • .Payment card data and billing records from ticket purchases
  • .Operational documents including flight operations data, crew scheduling, maintenance records
  • .Cargo manifests and freight documentation containing shipper and consignee details

FunkSec represents a new generation of ransomware operators leveraging AI to accelerate operations. The group uses AI-assisted code development for ransomware payloads, AI-generated victim communication, and automated reconnaissance.

PNR data reveals travel patterns, associations, and destination preferences that intelligence services consider among the most valuable categories of structured personal data.

03

SOURCES

Check Point Research, Cybernews, Dark Reading, Security Affairs

RELATED ANALYSIS

Conduent/SafePay: 25M Americans Exposed in 84-Day Ransomware Dwell - Largest US Government Data Breach
Jan 13, 2025 · 25M+ affected · 8.5TB exfiltrated · 84-day dwell
UAE Foils AI-Powered Ransomware Campaign - 200,000 Attacks/Day Intercepted
Feb 18-21, 2026 · 200K/day
University of Mississippi Medical Center: 35 Clinics Shut Down 9 Days by Ransomware
Feb 19 - Mar 2, 2026 · Healthcare
Passaic County, NJ: Medusa Ransomware Disables Government Services for 526,000 Residents
Mar 4, 2026 · 526K residents · $800K ransom
Omrania & Associates: INC Ransom Publishes 4TB of Saudi Critical Infrastructure Drawings
Jan 9, 2026 · 4TB published · Egis subsidiary
MORE RANSOMWARE →