What happened
Hawaiian Airlines confirmed in late June 2025 that a cyberattack had disrupted its IT systems, while stating that flights continued to operate safely. The FBI confirmed it was aware of Scattered Spider expanding its targeting to aviation after earlier focusing on retail and insurance. Researchers noted the incident matched the group's known tradecraft, though the airline did not formally attribute it.
How the deception worked
Scattered Spider's standard aviation playbook is to impersonate an employee or contractor in a call to the IT help desk and persuade the agent to reset credentials or enrol a new authenticator. The group also registers unauthorised devices against compromised accounts as a way of defeating multi-factor authentication, so that later logins look legitimate. Because airlines run large outsourced service desks covering shift workers and contractors around the clock, a caller claiming to be locked out mid-shift is a routine and hard-to-challenge request.
AI involvement · No AI reported
No AI-generated media was reported in this intrusion.
The control that would have caught it· our reading, not a claim from the sources
Strict, scripted caller-verification for account recovery and alerting on new device registrations against existing accounts are the controls that surface this pattern early.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.