News

SriLankan Airlines: A New Ransomware Group Is Claiming It Stole Engine Records, Flight Databases, and Staff Credentials

BLACKNET-00 Claims Cyberattack on SriLankan Airlines and Theft of Internal Data

BLACKNET-00 claims to have breached SriLankan Airlines and extracted credentials for flight operations systems, internal databases, employee records, network maps, and aircraft maintenance documentation, including engine records for Pratt & Whitney IAE V2500 engines and FAA airworthiness certificates. The claim was published on a dark web forum and promoted through Telegram. SriLankan Airlines has not confirmed the incident. KELA notes the group frequently promotes claimed victims through underground channels before independent verification is possible.

SriLankan Airlines has not confirmed the breach. BLACKNET-00 is a recently emerged group whose claims haven’t been fully independently verified. Both facts matter, and neither makes this story safe to ignore.

What BLACKNET-00 Claims to Have Taken

The group’s post is detailed in a way that goes beyond a typical extortion listing. Most ransomware groups publish a company name, a sector, and sometimes a sample file or two. BLACKNET-00 published a structured inventory.

On the systems side, they claim credentials for FTP, PRTG (the network monitoring platform commonly used in enterprise IT), RDP (remote desktop), the airline’s intranet, Outlook Web Access (OWA), and IMAP email servers. These aren’t one-offs. Access to these services would give an attacker live visibility into internal communications, the ability to log into employee accounts remotely, and a window into server performance and network structure.

They also name specific databases. The cluster includes ngcs-flights, ngcs-operations, ngcs-ghoperations, and ngcs-masters, the last described as a corporate database, alongside ngcs-rating, an internal rating system. In aviation IT, “NGCS” designations typically relate to Next-Generation Check-in System or ground-handling coordination systems. If the claim is accurate, these databases would contain passenger booking data, flight operations records, and ground handling coordination information.

System logs, including Log4j logs, are also listed. Log4j is the Java logging framework behind the Log4Shell vulnerability that led to mass exploitation across enterprises in 2021. Exposing Log4j log files can reveal additional system paths, IP addresses, and software versions that help attackers understand a target’s technical architecture.

The Aviation Safety Data Claim

This is the section of the BLACKNET-00 post that’s drawing the most scrutiny from aviation security researchers, and the one that needs the most careful framing.

The group claims to have obtained aircraft maintenance manuals, approved maintenance station lists, engine maintenance reports for Pratt & Whitney IAE V2500 engines, airworthiness certificates, and quality and safety audit records. One certificate in the listing carries the FAA identifier Z3EY983Y.

Let’s be specific about what this means and what it doesn’t.

Aviation airworthiness certificates, maintenance manuals, and engine records are sensitive documents. Stolen maintenance data could reveal how an airline manages its inspection schedules, which approved maintenance organizations it uses, and the current state of specific aircraft systems. That’s genuinely valuable intelligence for a sophisticated attacker targeting aviation infrastructure.

What it doesn’t mean, and what should be stated clearly, is that access to maintenance documentation doesn’t provide direct control over aircraft systems. Maintenance records and avionics are separate systems. As TorNews’s own analysis notes, “accessing stolen technical information does not directly imply a flight-safety threat.” Multiple layered certification and inspection processes separate documentation from operational airworthiness.

The more immediate risk from these specific documents is competitive intelligence and targeted social engineering; attackers who know an airline’s maintenance partners, approved station lists, and engine specifications can impersonate those suppliers convincingly.

Who BLACKNET-00 Is

The group is new. KELA’s threat intelligence team, which has tracked BLACKNET-00’s emerging activity, published an analysis describing it as part of a broader crimeware ecosystem where the group promotes BLACKNET-00 as a ransomware-as-a-service kit, a tool marketed to affiliates with limited technical backgrounds, offering encryption, data theft, security-solution evasion, and remote access capabilities in a single package.

This matters because it changes the threat profile. A custom-built ransomware operation run by an experienced criminal team is one thing. A kit-based operation marketed to low-skill affiliates is another. The latter group is harder to predict, more variable in tactics, and likely to verify claims less consistently before publishing them.

KELA also notes that BLACKNET-00’s other alleged victims include the US Federal Aviation Administration and an Egyptian real estate company โ€” a range that suggests opportunistic targeting rather than sector-specific expertise. The group primarily uses Telegram and underground forums rather than traditional dark web leak sites, which further complicates independent assessment of its claims.

The broader aviation sector has faced sustained attacks through 2025 and 2026. Qilin ransomware claimed Malaysia Airlines in February 2026. British Airways pilot data was breached. A separate incident in September 2026 exposed 220 million traveler records from an Advance Passenger Information System database linked to Vietnamese aviation infrastructure. Airlines handle uniquely rich data- names, passports, biometrics, seat assignments, travel histories, payment details- and that richness makes them persistent targets regardless of which group is doing the attacking.

The Bigger Problem With Unverified Claims

Even when ransomware claims prove false or exaggerated, they still cause harm. Here’s why.

An attacker who publishes a detailed-looking inventory of an airline’s systems, whether accurate or fabricated, gives social engineers a script. Employees receive targeted phishing emails referencing specific database names. Customers receive messages that mention FlySmiLes account details they haven’t publicly shared. The claim itself, regardless of its accuracy, becomes the raw material for downstream attacks.

This connects to a pattern we’ve seen in how dark web early warning signals operate: even announcing an attack creates a window of vulnerability before the target has publicly confirmed or denied anything.

SriLankan Airlines’ own security guidance page is clear about what to watch for: unexpected notifications about FlySmiLes account changes you didn’t make, confirmation emails for password changes you don’t recognize, and any contact from anyone claiming to be SriLankan Airlines support and asking for your login credentials. Go directly to SriLankan Airlines’ official password reset page rather than following any link in an email or message.

What’s Still Unknown

The fundamental questions remain unanswered. Did BLACKNET-00 actually access SriLankan Airlines’ internal network? Did they retrieve data from the databases they’ve named? Are the operational credentials they claim to hold still valid?

SriLankan Airlines has not published a breach notification or any security alert beyond its existing vulnerability disclosure page. If a breach occurred and customer data was accessed, GDPR-adjacent notification obligations under Sri Lanka’s Personal Data Protection Act would apply for customers in relevant jurisdictions. The absence of a formal notification doesn’t mean nothing happened; investigation timelines vary. It means the story is still developing.

Researchers at iQBlack have cautioned analysts to separate confirmed technical evidence from the operators’ claims. That’s the right frame here. BLACKNET-00 has published an inventory. An inventory isn’t a confirmed breach. But it’s enough to take seriously while the investigation runs.

For FlySmiLes members or anyone who uses SriLankan Airlines for frequent travel, the prudent response is the same as any potential credential exposure: change your password now using the official FlySmiLes reset page, enable any available two-factor authentication, and treat any inbound contact referencing your travel history or account details with immediate suspicion until SriLankan Airlines publishes an official update.

Our guide on what to do when your personal data may have been exposed covers the broader checklist for passengers in this situation.

Frequently Asked Questions

What is BLACKNET-00?

A recently emerged ransomware-as-a-service group that markets its toolkit to low-skill affiliates. KELA has documented its promotion of claimed victims through Telegram and underground forums.

What specifically did BLACKNET-00 claim to steal?

Credentials for FTP, RDP, OWA, PRTG, and intranet services; flight operations databases; employee records; network maps; aircraft maintenance manuals; engine records for Pratt & Whitney V2500 engines; and FAA airworthiness certificates.

Has SriLankan Airlines confirmed the breach?

No. The airline has not issued a public statement confirming or denying the claim as of September 29, 2026.

Does stolen maintenance data threaten flight safety?

No direct aircraft control is available through maintenance documentation. The risk is competitive intelligence exposure, targeted social engineering against maintenance partners, and operational intelligence for further attacks.

What should FlySmiLes members do?

Change your FlySmiLes password immediately at the official reset page. Enable two-factor authentication where available. Do not respond to any unsolicited contact claiming to be from SriLankan Airlines.

Muhammad Anas

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

๐Ÿ“‹ Latest Articles

View all →
Arizona Court System Cyberattack Exposes Personal Data of Residents
News

Arizona Court Phishing Attack Exposed Home Addresses of People With Protective Orders

A phishing email let a malicious bot access Arizona’s statewide judicial network and download a large volume of…

Sep 29, 2026
6 min read
Flink data breach LPG Group
News

Flink Was Breached And Now Hackers Are Emailing Its Customers for Ransom Too

LPG Group breached Flink using compromised employee login credentials and accessed an internal system containing names, email addresses,…

Sep 28, 2026
6 min read
LLM-Jacking
News

LLM-Jacking: The Dark Web Is Now Selling AI Access at 97% Off

Google’s Threat Intelligence Group has warned of a surge in two related AI-access attacks: credential theft targeting AI…

Sep 28, 2026
6 min read
Fraudsters Are Using Vacant Homes to Steal Your Mail. Here's the Full Playbook.
News

Fraudsters Are Using Vacant Homes to Steal Your Mail. Here’s the Full Playbook.

Threat actors are identifying vacant homes using platforms like Zillow and Rightmove, registering for USPS Informed Delivery at…

Sep 27, 2026
7 min read
A New AI System Reads the Dark Web the Way Human Analysts Do Across Text and Images at Once
News

A New AI System Reads the Dark Web the Way Human Analysts Do Across Text and Images at Once

Researchers at G.H. Raisoni University published a study in Neural Computing and Applications this week describing a multimodal…

Sep 27, 2026
6 min read
Fujitsu and KELA Are Bringing Dark Web Intelligence to Japan's Corporate Security Front Line
News

Fujitsu and KELA Are Bringing Dark Web Intelligence to Japan’s Corporate Security Front Line

Fujitsu Limited launched a three-component cybersecurity service on September 25, 2026, combining dark web monitoring, attack surface management,…

Sep 25, 2026
6 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted