Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Malaysia Airlines Listed by Qilin Ransomware Group — Passenger Data at Risk
Malaysia Airlines Listed by Qilin Ransomware Group — Passenger Data at Risk
NEWS

Malaysia Airlines Listed by Qilin Ransomware Group — Passenger Data at Risk

The Qilin ransomware-as-a-service group has listed Malaysia Airlines on its leak site, claiming access to passenger records, personnel files, and...

Dylan H.

News Desk

March 22, 2026
4 min read

Qilin Ransomware Group Claims Malaysia Airlines as Latest Victim

The Qilin ransomware-as-a-service (RaaS) group listed Malaysia Airlines on its dark web leak site on February 26-27, 2026, claiming to have exfiltrated sensitive data including passenger records and operational documents. The airline has not confirmed the breach, but the claim raises serious concerns given Qilin's documented history of targeting Malaysian aviation infrastructure.


AttributeValue
Threat ActorQilin (RaaS)
VictimMalaysia Airlines
Claim DateFebruary 26-27, 2026
ConfirmationUnconfirmed by Malaysia Airlines
Data ClaimedPassenger records, personnel files, contracts, operations docs
Proof PublishedNone at time of listing
Previous TargetKLIA airport (March 2025, confirmed)

Claimed Data Exfiltration

According to the leak site listing, Qilin claims access to:

  • Passenger booking and contact records — names, flight itineraries, contact details
  • Personnel files — employee records including background check data
  • Vendor contracts — agreements with service providers and partners
  • Operational documents — internal airline procedures and communications
  • Internal communications — emails and messaging data

Pattern of Aviation Targeting

This claim follows a confirmed Qilin ransomware attack against Kuala Lumpur International Airport (KLIA) in March 2025, which:

  • Disrupted flight information displays for over 10 hours
  • Knocked out check-in counters and baggage systems
  • Prompted a $10 million ransom demand that Malaysia's Prime Minister publicly refused to pay
  • Caused cascading delays across Southeast Asian air travel

The repeated targeting of Malaysian aviation infrastructure suggests either a persistent focus by a specific Qilin affiliate or an ongoing access foothold in the sector.

About Qilin Ransomware

Qilin operates a ransomware-as-a-service model where affiliates deploy malware and leverage shared negotiation infrastructure in exchange for a percentage of ransom payments. The group has been responsible for over 700 attacks across critical sectors globally.


Impact AreaDescription
Passenger PrivacyMillions of booking records potentially exposed
Employee SafetyPersonnel files and background checks at risk
Operational SecurityInternal procedures could aid future attacks
RegulatoryPotential PDPA (Malaysia) and international data protection violations
Aviation SectorSecond Qilin attack on Malaysian aviation in 12 months

Recommendations

For Affected Passengers

  • Monitor bank and credit card statements for unauthorized activity
  • Be alert for phishing emails referencing Malaysia Airlines bookings
  • Consider placing fraud alerts on credit files if you flew Malaysia Airlines recently

For Aviation Organizations

  • Audit network segmentation between passenger systems and operational technology
  • Implement enhanced monitoring for Qilin indicators of compromise
  • Review third-party vendor access and credentials
  • Ensure offline backups of critical reservation and operations systems

Key Takeaways

  1. Qilin's claim against Malaysia Airlines is unconfirmed but follows a documented pattern of targeting Malaysian aviation
  2. The KLIA attack in 2025 was confirmed and caused significant operational disruption with a $10 million ransom demand
  3. Passenger data is the primary concern — booking records, contact information, and travel itineraries
  4. No proof of data has been published on the leak site, which is sometimes used as a pressure tactic
  5. Aviation remains a high-value target for ransomware groups due to operational sensitivity and regulatory pressure to pay

Sources

  • Malaysia Airlines claimed by Qilin ransomware — Cybernews
  • Malaysia Airlines allegedly breached by Qilin — SC Media
  • Qilin Ransomware Victim: Malaysia Airlines — RedPacket Security
  • Malaysia PM says country rejected $10 million ransom demand — The Record
#Ransomware#Qilin#Aviation#Data Breach

Related Articles

Covenant Health Ransomware Attack Impacts 478,000 Patients

Qilin ransomware group claims responsibility for massive healthcare breach, stealing 850GB of sensitive patient data across multiple states. Initial...

3 min read

Two US Cybersecurity Professionals Plead Guilty to BlackCat Ransomware Attacks

Former incident responder Ryan Goldberg and ransomware negotiator Kevin Martin admitted to running ALPHV/BlackCat ransomware operations against five US...

3 min read

Marquis Fintech Breach Exposes 672,000 Banking Customers via SonicWall Exploit

Plano-based fintech vendor Marquis disclosed that a ransomware attack exploiting a SonicWall firewall vulnerability compromised Social Security numbers,...

4 min read
Back to all News