Article Details

Scrape Timestamp (UTC): 2024-08-26 18:32:43.607

Source: https://www.theregister.com/2024/08/26/seattle_airport_cyberattack/

Original Article Text

Click to Toggle View

Seattle airport 'possible cyberattack' snarls travel yet again. No word yet on if ransomware is to blame. The Port of Seattle, which operates the Seattle-Tacoma International Airport, is investigating a "possible cyberattack" after computer outages disrupted the airport's operations and delayed flights. The internal internet and web systems outage occurred early Saturday morning, according to an Xeet by the official account belonging to the airport, which serves as a traffic hub for Alaska Airlines and Delta Air Lines.  In a subsequent Xeet, the Port of Seattle confirmed it had "isolated critical systems and is in the process of working to restore full service and do not have an estimated time for return." The disruptions continued through Sunday, with the airport urging travelers to check in before arriving at Sea-Tac, and give themselves extra time to get to their gates. We're told terminal screens were also experiencing technical difficulties, adding to the disruption. Airport goers reported long lines as multiple airlines issued tickets by hand, and local media said "thousands" of travelers were affected. As of Monday, the Port's website remained offline. While airport and port authorities did not immediately respond to The Register's inquiries about the cyberattack, including whether it was a ransomware infection, the transportation authorities told ABC that the federal government was involved in the probe. "We are conducting a thorough investigation with the assistance of outside experts," Lance Lyttle, aviation managing director at Seattle-Tacoma International Airport, said in a statement.  "We have contacted and are working closely with federal partners, including TSA and Customs and Border Protection," Lyttle added. The likely cyberattack comes as ransomware gangs batter critical infrastructure including transportation organizations.  Of the 395 ransomware attacks claimed by criminals in July, more than a third (125 or 34 percent) targeted these critical industries, according to NCC Group.  The researchers noted that these essential services and facilities make them "valuable targets" to financially motivated criminals, and said "ransomware actors pressure these targets into payment, exploiting their need to remain operational." Plus, to make matters worse for weary travelers, the weekend cyberattack comes a month after a faulty CrowdStrike update caused a global outage that also snarled flights at airports around the world.

Daily Brief Summary

CYBERCRIME // Seattle Airport Disrupted by Suspected Cyberattack, Investigation Ongoing

A potential cyberattack on Seattle-Tacoma International Airport caused significant disruptions, impacting flight operations and causing delays.

Outages affecting the airport's internal internet and web systems began early Saturday, with ongoing issues through the weekend.

The Port of Seattle has isolated critical systems to safeguard against further damage and is working vigorously to restore full functionality.

Due to system failures, terminal screens malfunctioned, and airlines resorted to issuing tickets manually, leading to extensive lines and traveler delays.

As of Monday following the incident, the Port of Seattle's website was still down, indicating continued challenges in recovery efforts.

The federal government has joined the investigation, with agencies like TSA and Customs and Border Protection lending their expertise.

This incident highlights a broader trend of ransomware attacks targeting critical infrastructure, with transportation being a prime target due to its operational importance.

The unscheduled downtime this month follows another significant disruption linked to a faulty update from cybersecurity firm CrowdStrike last month, reflecting ongoing vulnerability in airport operations to cyber events.