A newly emerged ransomware group claims it breached Star Aviation, a Kentucky aerospace supplier that supports Boeing and Airbus aircraft. The attackers allegedly stole technical schematics and employee identity documents, raising concerns about fraud and targeted attacks.

Storm ransomware lists Star Aviation as a victim

The group, known as Storm, added Star Aviation to its leak site on September 2.

Star Aviation repairs and tests engine wire harnesses and electronic wire interconnect systems used in commercial aircraft. The company also develops specialised repairs and replacement parts that can receive Federal Aviation Administration approval.

The ransomware group released sample data to support its claim. Cybernews researchers examined screenshots that appeared to show internal technical schematics and possible employee ID cards.

Star Aviation has not confirmed the alleged breach. The full scope of any data theft also remains unknown.

Leaked schematics could increase aviation risks

The alleged Star Aviation breach is significant because of the company’s place in the aviation supply chain.

Electrical wiring and electronic interconnect systems support aircraft reliability and operational readiness. Stolen diagrams would not necessarily enable a remote attack on an aircraft. However, they could provide valuable technical intelligence for criminals targeting aviation organisations.

Attackers could combine those documents with other stolen information to plan phishing campaigns, social engineering attempts or further intrusions.

The apparent exposure of employee ID cards creates additional risks. Criminals could use identity documents to commit fraud or impersonate staff in targeted scams.

Storm ransomware is a new but active group

Storm ransomware first appeared in August 2026. Ransomware monitoring services have linked the group to roughly 44 to 48 claimed victims since then.

Its reported victims operate across healthcare, financial services, manufacturing, technology, transportation and government. Most recorded targets are based in the United States.

The Star Aviation breach claim adds an aerospace supplier to that list. Organisations in the aviation sector should monitor the incident closely and remain alert to impersonation attempts that may use stolen employee or technical information.


0 responses to “New ransomware gang claims breach at Boeing and Airbus supplier”