Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Business Risk Intelligence: An Aviation Necessity during the Holidays and Beyond

by The Gurus
January 5, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

As an estimated 3.5 million Britons packed their suitcases and flew home for the winter break, the airline industry was working hard to ensure the holiday travel season ran smoothly. Airport delays are no one’s idea of holiday fun, and flight disruption is a major financial and reputational risk for airlines worldwide. However, the aviation sector’s high-profile visibility and wealth of customers’ sensitive personal data appeal to the agendas and motivations of a wide range of adversaries.

With everything from flight schedules and IT systems to passport data and customers’ frequent flyer miles under threat, airlines need to proactively address the risks that they face to protect their business. An increasingly valuable tactic is the use of Business Risk Intelligence (BRI) gleaned from the Deep & Dark Web, which can help airlines identify and mitigate risks before they become a reality.

The dark web travel bureau

Thanks to the prevailing geopolitical climate and lasting impact of post-9/11 security concerns, airlines require passengers to provide a wealth of personal information, from passport numbers and birth dates to bank details and travel itineraries. This information is highly desirable among cybercriminals who can profit by stealing and selling it on the Deep & Dark Web. Unsurprisingly, airlines experience up to 1,000 cyberattacks per month from threat actors targeting passenger data. Passengers whose personal information is compromised are at risk of identity fraud, which can have devastating consequences for the individuals affected and cause a damaging breakdown of trust and confidence between passenger and airline.

Interestingly, it’s not always the obvious information, such as passport details, that is the target. In 2015, a major U.K. airline’s frequent flyer accounts were breached by cybercriminals attempting to steal air miles. Illicit schemes of this sort are often developed in the forums of the Deep & Dark Web. In fact, for some time Flashpoint analysts have been tracking the discussions of cybercriminals who are running fraudulent travel bureau services using stolen reward points. Purchases ranging from flights, hotels, and car rentals to gift cards can be made using the stolen points. Being aware of emerging cybercriminal activity can give airlines an advantage over adversaries in their efforts to strengthen their security perimeter and protect customer data.

Taking action on activists

Airline disruption can take many forms, but one of the more low-tech challenges is managing the protests that may accompany airport expansions and other major developments. Using relatively simple obstruction tactics, activists can cause significant disruption for passengers. In February 2017, members of one activist group targeted a major U.K. airport in protest over its plans to build a third runway. Passengers experienced inconvenient delays as the protestors blocked an access tunnel in the airport’s road network. Similar protests at other European airports have caused flight cancellations and terminal shutdowns. Campaigns like this are not uncommon, and evidence of their planning can often be found in Deep & Dark Web forums. Skilled multilingual analysts monitoring these forums are able to identify the protest campaigns that are growing in momentum and those which are fading. Analysts can also look for indications of whether planned protests are likely to involve vandalism or significant risk to safety of passengers or indeed the protestors themselves. This intelligence can be used by airlines to proactively manage protest situations safely and minimise their impact on flights and passengers.

 

Safeguarding the aviation supply chain

The aviation industry faces particular challenges due to its geographically dispersed and cross-border operations. There are a multitude of points—both technological and physical—where threat actors can infiltrate the supply chain and cause serious problems. In a recent example, our analysts identified threat actors using tactics that are more commonly targeted at banks and online retailers to phish the supply chain credentials of a number of shipping companies. This allowed them to generate fraudulent payments and invoices and even physically control and divert shipments of goods, giving them their own distribution system for whatever else they might choose to transport—a potentially catastrophic security breach for airlines. Fortunately, in this case, we were able to identify the companies being targeted and provide them with examples of the phishing tactics being used so that they could advise partners to be aware of a potential breach and strengthen their security posture against this strategy.

At its best, air travel is fast, convenient, and the gateway to a fantastic holiday. By leveraging BRI to reduce the risk of data theft and flight disruption, airlines are aiming to ensure that all passengers need to worry about is their baggage allowance.  BRI puts airlines in the pilot’s seat when it comes to proactively managing threats to their passengers, business, and reputation, ensuring that travellers can enjoy a safe and stress-free getaway.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Blockchain, virtualization and the rise of AI

Next Post

Amazon servers slowed down after Intel vuln patch

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol