{"id":7786,"date":"2025-10-19T10:03:28","date_gmt":"2025-10-19T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/19\/american-airlines-subsidiary-envoy-compromised-in-oracle-hacking-campaign\/"},"modified":"2025-10-19T10:03:28","modified_gmt":"2025-10-19T10:03:28","slug":"american-airlines-subsidiary-envoy-compromised-in-oracle-hacking-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/19\/american-airlines-subsidiary-envoy-compromised-in-oracle-hacking-campaign\/","title":{"rendered":"American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign"},"content":{"rendered":"<p>    American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle\u2019s E-Business Suite (EBS).<\/p>\n<p>The breach, first highlighted by the notorious <a href=\"https:\/\/cybersecuritynews.com\/clop-ransomware-gang\/\" target=\"_blank\" rel=\"noreferrer noopener\">Clop ransomware<\/a> group, underscores the growing risks facing enterprise software in the aviation sector.<\/p>\n<p>Clop, known for high-profile extortion schemes like the <a href=\"https:\/\/cybersecuritynews.com\/moveit-transfer-systems-under-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">MOVEit Transfer<\/a> attacks, claimed responsibility last week, listing American Airlines among over 60 organizations hit through unpatched flaws in Oracle EBS.<\/p>\n<p>The group, which operates out of Russia-linked networks, has demanded ransoms in cryptocurrency, threatening to leak stolen data on its dark web site if unpaid.<\/p>\n<p>While Clop didn\u2019t specify the exact vulnerabilities, security researchers point to known issues in Oracle\u2019s WebLogic Server and EBS modules, such as <a href=\"https:\/\/cybersecuritynews.com\/weblogic-server-flaw-poc-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-21931<\/a>, which allow remote code execution if not properly secured.<\/p>\n<p>Envoy\u2019s admission came swiftly after the claims surfaced, aiming to reassure stakeholders amid rising concerns over aviation data security.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-envoy-compromised\"><strong>Envoy Compromised<\/strong><\/h2>\n<p>\u201cWe are aware of the incident involving Envoy\u2019s Oracle E-Business Suite application,\u201d an Envoy spokesperson told Cybersecurity News. \u201cUpon learning of the matter, we immediately began an investigation and law enforcement was contacted\u201d.<\/p>\n<p>\u201cWe have conducted a thorough review of the data at issue and have confirmed no sensitive or customer data was affected. A limited amount of business information and commercial contact details may have been compromised.\u201d<\/p>\n<p>The spokesperson emphasized that passenger records, flight operations, and personal identifiable information remained untouched, mitigating immediate risks to travelers.<\/p>\n<p>However, the exposure of internal business data could still pose challenges, including potential <a href=\"https:\/\/cybersecuritynews.com\/phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a> vectors or competitive intelligence leaks for the regional carrier, which operates over 150 aircraft and serves millions of passengers annually under the American Airlines banner.<\/p>\n<p>Experts warn that this incident highlights systemic vulnerabilities in legacy enterprise systems. <a href=\"https:\/\/cybersecuritynews.com\/oracle-security-update-334-patches\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oracle EBS<\/a>, widely used for HR, finance, and supply chain management, has faced criticism for slow patching cycles.<\/p>\n<p>Cybersecurity firm Mandiant noted in a recent report that Clop\u2019s tactics often target third-party software to amplify reach, affecting not just direct victims but entire ecosystems.<\/p>\n<p>As investigations continue with federal authorities, including the FBI\u2019s cyber division, Envoy stated it has implemented enhanced monitoring and updated its Oracle systems. American Airlines, while not directly named in data leaks, has bolstered its subsidiary\u2019s defenses in response.<\/p>\n<p>This breach arrives amid a wave of aviation cyberattacks, from <a href=\"https:\/\/cybersecuritynews.com\/heathrow-european-airports-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware hitting airports<\/a> to state-sponsored espionage. Industry leaders are urging faster adoption of zero-trust architectures to safeguard critical infrastructure.<\/p>\n<p>For now, Envoy passengers can fly with relative peace of mind, but the event serves as a stark reminder: in cybersecurity, one weak link can ground an entire operation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/envoy-compromised-oracle-campaign\/\">American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/envoy-compromised-oracle-campaign\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign Envoy Air, a wholly owned subsidiary of American Airlines, has confirmed it fell victim to a hacking campaign exploiting vulnerabilities in Oracle\u2019s E-Business Suite (EBS). The breach, first highlighted by the notorious Clop ransomware group, underscores the growing risks facing enterprise software in the aviation sector. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-7786","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7786"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7786"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7786\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}