Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » BLACKNET-00 Claims Cyberattack on SriLankan Airlines and Theft of Internal Data

BLACKNET-00 Claims Cyberattack on SriLankan Airlines and Theft of Internal Data

By:
Last updated:September 28, 2026
Human Written
  • Ransomware group BLACKNET-00 has allegedly breached SriLankan Airlines and stolen credentials, technical records, databases and internal documents.

  • The alleged data includes aircraft maintenance information, network maps, employee records and aviation safety documents.

  • SriLankan Airlines has not confirmed the incident, while researchers continue to assess the claims and capabilities of BLACKNET-00.

BLACKNET-00 Claims SriLankan Airlines Hack and Theft of Internal Data

In a recent post, the BLACKNET-00 ransomware gang claimed it hacked SriLankan Airlines and obtained confidential insider data. Reportedly affected data comprises credentials for operating systems, maintenance data, information on the network, and corporate information.

This group shared information about the incident on a dark web forum and provided a list of files and systems it accessed. SriLankan Airlines has not acknowledged the event yet, and thus, law enforcement cannot confirm the claims of the attackers.

BLACKNET-00 Claims Access to Airline Systems

According to the threat actor, the alleged intrusion reached several parts of the internal network of SriLankan Airlines. The group claims it extracted credentials linked to FTP, PRTG, RDP, Intranet, OWA and IMAP services. The list also includes SSL certificate files and internal software installation packages. BLACKNET-00 further claims access to operational and training documents.

Many of the airline management systems surface in the alleged dataset, including ngcs-flights, ngcs-operations, and ngcs-ghoperations. The group claims the presence of the ngcs-masters database, which is a corporate one, as well as ngcs-rating, the internal rating system. Allegedly, the group was able to obtain system logs, including Log4j, and internal e-mails.

The claims of information exposure are more than just regular business documents. BLACKNET-00 insists they have access to the internal network map and server permissions of the airline. Moreover, the group claims to have obtained employee information, job numbers, supplier agreements, and business agreements. Such data can furnish hackers with crucial information about employees and business connections of the airline.

However, the claims do not establish that every listed system suffered a compromise. Threat actors often publish large inventories during extortion campaigns – so researchers must verify such claims before treating them as confirmed breaches. Cyber threat intelligence platform, KELA, has also noted that BLACKNET-00 frequently promotes claimed victims through underground channels.

Alleged Aviation Data Raises Security Concerns

The most sensitive part of the claim involves aircraft and maintenance information. BLACKNET-00 says it stole maintenance manuals, approved maintenance station lists and agent information. The group also claims access to engine maintenance reports involving Pratt & Whitney IAE V2500 engines. It says the stolen material includes other technical documents linked to aircraft operations.

The alleged dataset also contains airworthiness certificates and quality and safety audit records. One listed certificate carries the identifier FAA: Z3EY983Y. If investigators confirm these claims, the data could create risks beyond normal corporate data theft. Maintenance documents can reveal how an airline manages aircraft and technical procedures.

Information about the network could help attackers recognize the design of internal systems. With authentication credentials, there is also a different point of danger if it remains valid or if employees utilize them too often. However, accessing stolen technical information does not directly imply a flight-safety threat. Aviation entities engage multiple methods and systems to maintain aircraft airworthiness.

SriLankan Airlines employs endpoint detection and response, vulnerability assessments, and security information and event management technologies. According to its published security information, the airline utilizes AI and machine learning to boost its cyber defenses.

The current fleet information of the company consists of Airbus A320 and A321 packages as well as A330 aircraft. Also, the available fleet documentation provides detailed technical specifications of multiple aircraft types.

The Hacker Group BLACKNET-00 Expands Its Ransomware Activity

Recently, BLACKNET-00 has gained popularity as a ransomware gang and is part of a larger crimeware ecosystem. KELA announced that the gang is promoting BLACKNET-00 as a ransomware kit that lowers the level of technicality for attackers. The criminals are advertising the kit as a tool that demands little programming knowledge. The advertised features include encryption, data stealing, avoiding security solutions, and remote access options.

Further, KELA stated that the alleged victims of the group belong to various sectors and countries. The reported targets include the US Federal Aviation Administration and a company from Egypt that deals with real estate. It seems that BLACKNET-00 does not stick to traditional leak sites for every compromise. Instead, it utilizes Telegram and underground forums for promoting its alleged hacks.

Therefore, the SriLankan Airlines claim fits a wider pattern of public breach announcements. Such posts can pressure organizations by threatening to release stolen information.

Threat intelligence researchers have warned that some BLACKNET-00 capability claims still need independent technical validation. iQBlack, for example, said analysts should separate confirmed technical evidence from claims made by the operators.

That distinction matters in the SriLankan Airlines case. The list from the threat actor looks extensive, but the public information does not yet prove that attackers accessed every named system.

Investigation Needed Before Breach Can Be Confirmed

SriLankan Airlines has not publicly confirmed the alleged BLACKNET-00 intrusion at the time of reporting. That leaves several important questions unanswered. Investigators need to establish whether attackers entered the network of the airline, what systems they reached, and whether they actually removed data.

A separate airline-related claim also alleges extensive access to internal systems, as covered in our recent report where a hacker claimed full control of a major Asian Airline’s booking system.

They also need to determine whether any exposed credentials remain active. If attackers obtained valid access details, the airline would need to reset affected accounts and certificates. The airline has already published guidance for security concerns involving customer accounts. Its security page tells customers to change their FlySmiLes passwords if they suspect account compromise.

In the meantime, security teams will have to monitor leaks of IDs, documents, and events related to the breach. They may also monitor the dark web for proof of the breach.

The aviation sector remains an attractive target for hackers because the industry handles sensitive personal, operational, and financial information. Thus, a break-in may have an effect on the systems of a company, despite the attackers not getting access to the control systems of aircraft.

For now, the claims from BLACKNET-00 remain just allegations. Evidence from SriLankan Airlines, independent investigators, and law enforcement agents will serve as the major grounds for making a conclusion.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.