← AIRBUS

2023 Airbus — customer portal account abuse; ~3,200 supplier contacts exposed (USDoD / BreachForums)

2023 3.2K records affected Share on X

Data compromised

Business-contact style fields for suppliers/vendors and customer portal–scoped documents described in press (names, addresses, phones, emails cited)

Technical writeup

In September 2023, coverage in The Record, The Register, Krebs on Security, and SecurityWeek described Airbus investigating publication of data tied to roughly 3,200 suppliers/partners after a threat actor (“USDoD”) claimed access via a compromised customer/airline-side IT account used to reach an Airbus web portal for that customer’s documents. Airbus publicly framed the issue as abuse of credentials associated with a customer account downloading customer-specific portal material—not Airbus’s enterprise-wide mass breach—and emphasized containment steps. Victim counts and field-level detail in underground marketing should be read as actor-claimed where not independently itemized.

Root cause

Credential compromise on a customer account permitted unauthorized document retrieval from Airbus customer-facing portal (per company and trade-press narrative)

References