Cyberattacks in aviation

Lessons from the latest threats

The aviation industry faces unprecedented cyber risk as integrated technologies and interconnected systems become the foundation of modern flight operations, air traffic control, passenger services, and maintenance.

While these platforms improve efficiency, they also create vulnerabilities — where a single point of failure can disrupt multiple critical systems. Compounding this risk, many airlines still rely on legacy systems lacking updated security features, making them targets for cyberattacks.

Threat actors range from sophisticated nation-state conducting espionage and sabotage to criminal networks seeking financial gain through ransomware and data theft. Aviation’s critical infrastructure can attract attackers whose actions can result in potentially significant costs of operational downtime and regulatory non-compliance. Airlines must also comply with data protection laws, such as GDPR and CCPA, adding another layer of risk and complexity.

Notable increase in social engineering-related cyberattacks

There has been a notable increase in cyberattacks that use social engineering as an initial entry point, with threat actors actively employing these tactics against large global organizations, including those in the aviation sector.

For example, threat actors expertly target IT help desks using sophisticated social manipulation techniques, including adopting local accents and leveraging publicly available employee information to convince staff to reset accounts, even those protected by multi-factor authentication (MFA). They may also purchase insider access to gain network entry simply by logging in.

Once inside a network, the threat actors can be difficult to detect and evict, as they will often leverage their control over legitimate accounts and exploit single sign-on (SSO) to access additional services. They also operate through infrastructure that mimics legitimate traffic from major mobile carriers and internet providers, complicating containment efforts.

What comes next, whether exploitation of virtualization management systems (which manage virtual machines on host systems), manual deployment of ransomware demands, double extortion attempts, denial-of-service (DDoS) attacks as diversion, or use of media to apply pressure on the organization attacked, appears to reflect threat actors’ mix of motivations that include desire for financial gain, “bragging rights,” and causing chaos.

Practical steps to help reduce cyber risk

1. Have visibility across all your devices: Continuous monitoring and threat hunting are key. Proactive monitoring using behavioral analytics can detect abnormal activity early, such as unusual data transfers or privilege escalations linked to attackers’ reconnaissance phases.

2. Bolster cybersecurity basics: To enhance your security posture against threats like social engineering, understand what exists on your network edge, as most network intrusions result from easily exploitable vulnerabilities. Having a human in the loop to monitor and respond to alerts can help to address potential threats promptly and effectively.

3. Prioritize employee awareness and training: Regular, targeted training, alongside AI-powered email security platforms, can identify and block phishing attempts. IT and customer help desks should be trained to detect social engineering attempts.

4. Test your incident response plan by conducting a tabletop exercise: Develop a comprehensive incident response plan that outlines roles and responsibilities for cyberattack scenarios. Conduct regular tabletop exercises to review and practice responses to hypothetical cyber incidents. This will help your team develop a form of “muscle memory” for incident response, enabling them to make quicker and more effective decisions.

5. Sign up for Marsh Central or another out-of-band communication platform: Threat actors are known for compromising communication platforms to obtain information about the company, employees, and incident response strategies. Marsh Central is a unified claims and incident management preparation and response platform.

6. Make lateral movement difficult: In the event of a breach, make lateral movement within the network as difficult as possible by implementing network segmentation to protect your most critical assets — your “crown jewels” — which typically include virtualization environments. Immediate patching and upgrading of VPN and RDP services, combined with enforcing multi-factor authentication (MFA), can help to prevent easy lateral movement.

7. Implement zero-trust network architecture: Restrict internal network access to only what is strictly necessary, with continuous verification, to aim to minimize damage from compromised accounts. While security will always involve a trade-off between user accessibility and protection, there are likely to be few instances where a user forgets both their password and loses access to their mobile device. Organizations should review their playbooks to determine whether it is possible to reset both factors in a single session. If an employee has lost both their mobile device and password, it may be appropriate to require them to come into the office to reset their password.

8. Conduct regular backup testing and segmentation: Frequent, secure, and tested backups — isolated from the main network — can facilitate recovery without paying ransoms.

9. Carry out supply chain security due diligence: Regular cybersecurity assessments of third-party vendors and tightening network segmentation between retailer systems and external partners can reduce indirect attack surfaces.

Why now is a good time to buy cyber insurance

Cyber insurance rates have generally decreased despite ongoing losses. In the last quarter of 2025, rates decreased by 7% globally, with declines across every region.

Insurers have increasingly focused on technical underwriting in response to the growing complexity of cyber risks. Capacity generally remains stable globally, with many insurers offering broader protection, such as technology errors and omissions (E&O) coverage, and higher coverage limits.

Given the rising potential for significant financial losses, you will want to see that your cyber insurance coverage takes account of the current risk environment and your risk appetite. A review of your policy can help to identify potential enhancements and assess your level of protection against a range of cyber incidents, including data breaches, ransomware attacks, and resulting business interruption.

Not if, but when

Recent attacks demonstrate how sophisticated, multi-stage intrusions can begin through simple means. Events are typically not highly targeted and do not involve extensive reconnaissance, making anyone a potential victim.

Investing in robust access controls, well-practiced incident response plans, and building a culture of cybersecurity awareness can help to build a stronger defense against persistent threat actors. In addition, a review of your organization’s current cyber insurance policy will help you to assess its alignment with your risk profile.

Marsh’s multi-disciplinary team is here to assist you in navigating this complex landscape and to help you pursue tailored solutions that meet your specific needs.

Authored by


Helen Nuttall Head of Cyber Incident Management, Marsh Risk

Serena France-Hayhurst UK Cyber Placement Leader, Cyber Risk, Marsh Risk

James Tytler Senior Associate, Cyber Incident Response, S-RM

Part 3: Aviation insurance market overview

Previous page

Terms of Use Privacy Notice Accessibility Cookie Notice

© 2026 Marsh. All Rights Reserved.