DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Incidents

Safran Group Leaks Sensitive Data

March 16, 2023
Reading Time: 2 mins read
in Incidents

 

The French-based aviation firm, Safran Group, suffered a data breach caused by a misconfiguration of its systems.

The breach made it vulnerable to cyberattacks for around 18 months. Sensitive information was leaked, including the Laravel app key, MySQL credentials, Simple Mail Transfer Protocol credentials, and the JSON Web Token key.

These could have given cyber criminals access to the company’s database, confidential documents, and employee computers. They could also have launched malicious attacks, including web shells or stolen the company’s equipment.

As one of the top aerospace suppliers, with revenues in excess of €19bn, Safran Group’s leak could have impacted not just the company, but also its customers in the aviation sector.

Safran Group has already experienced cyberattacks in the past. In 2011, cyber criminals attempted to map the company’s computer system between 2009 and 2010, and in 2018, there was another attempt on the company’s internal network.

Hackers believed to be linked to a state security ministry in China were suspected of collaborating with six hackers and two insiders at the Chinese office to steal jet engine blueprints.

The aviation industry is a prime target for cybercriminals because of its critical infrastructure. The industry has already experienced disruptions this year, such as when an alert system responsible for notifying pilots and airlines of potential dangers experienced a glitch that resulted in the temporary suspension of domestic flights throughout the US.

In February, Scandinavian Airlines suffered a cyberattack that knocked its website and mobile app offline for multiple hours. Anonymous Sudan claimed responsibility for this attack.

Cybernews has urged Safran Group to change leaked credentials and increase security measures.

It is essential that the keys used are in longer bit-lengths and encoded using secure encryption or hashing algorithms. The company should consider whether its platform needs to be accessible through the internet or only through a VPN, which would provide an additional layer of security.

Due to Safran Group’s position in the aviation supply chain, with only one hop between the company and the aircraft builders that use its products, a supply-chain attack could have a far-reaching impact, posing a risk to the company and its customers in the aviation sector.

Read More

Tags: ChinaCyber Attackscyber criminalsCYBER THREATSData BreachData exposedincidentsIncidents 2023March 2023Safran GroupSensitive data
1
VIEWS
ADVERTISEMENT

Related Posts

LockBit Ransomware Targets Sheriff’s Office

LockBit Ransomware Targets Sheriff’s Office

March 31, 2023
NCB Management Services reports data breach

NCB Management Services reports data breach

March 31, 2023
Misconfigured Microsoft app allowed attacks

Misconfigured Microsoft app allowed attacks

March 31, 2023
Hacking group tied to Russia & Belarus

Hacking group tied to Russia & Belarus

March 31, 2023

More Articles

Book

The Secure UX Enterprise

June 23, 2022
Incidents

Data breach at Colorado university impacts 30,000 students

October 27, 2021
Incidents

Multi-Color Corporation Discloses Data Breach

November 2, 2022
Course

Global Cybersecurity Foundations: Cybersecurity 101 for Managers and Directors

January 3, 2022

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.