Korean Air is South Korea's flag carrier and largest airline.
Overview
Korean Air is South Korea's flag carrier and largest airline. In cybersecurity terms, it has recently suffered data exposure—user/employee PII leaked by the Cl0p extortion group—and is also listed as a victim in an Oracle E-Business Suite (ERP) breach, underscoring multi-vector risk to its IT/ERP environments and sensitive employee data.
Related Threat Clusters
-
Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM
The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP…
28 articles · Updated July 24, 2026 -
Clop Ransomware Group Breaches University of Phoenix Data of 3.5 Million
The University of Phoenix experienced a data breach affecting 3.5 million individuals, attributed to the Clop ransomware group exploiting a zero-day vulnerability in Oracle's enterprise software. The attackers accessed…
3 articles · Updated December 30, 2025 -
Cl0p Gang Breaches Korean Air, Exposing 30,000 Employee Records
Korean Air has confirmed a significant data breach affecting the personal records of 30,000 employees. The Cl0p ransomware group targeted a catering partner, leading to the unauthorized leak of sensitive data. The…
1 article · Updated December 31, 2025
Recent Intelligence Reports
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — Bleepingcomputer · July 24, 2026
- 30,000 Korean Air Employee Records Stolen as Cl0p Leaks Data Online — Hackread · December 31, 2025
- Latest Oracle EBS Victims Include Korean Air, University of Phoenix — Thecyberexpress · December 30, 2025