logo

Korean Air discloses data breach after the hack of its catering and duty-free supplier

ID: 988337f4-80ed-5b5d-ac74-bd4078353196

STIX ID: report--988337f4-80ed-5b5d-ac74-bd4078353196

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2025-12-29

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Korean Air disclosed that roughly 30,000 employee records were exposed after its catering and duty-free supplier KC&D was hacked; the Clop ransomware group claimed responsibility and allegedly published the stolen data. Korean Air reported no customer data loss, has notified authorities, implemented emergency measures, and is investigating while reviewing partner security. The incident is linked in the article to Clop's ongoing exploitation of an Oracle EBS zero-day (CVE-2025-61882) and situates this breach within Clop's larger campaign of high-impact data thefts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.