FlyDubai data hijacked: hackers threaten to dump pilot data
All the pilot training materials were stolen.

Image by Cybernews
- Everest ransomware claims it stole 4.36GB of data from FlyDubai, including 2,862 employee records.
- The alleged data includes pilot training materials, operational directives, and records spanning 2009 to 2020.
- Everest also claims it has Boeing software source code and confidential aviation documents.
- Cybernews researchers warn the alleged leak could support phishing, social engineering, and legal or reputational risks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
FlyDubai's cockpit secrets may soon hit the dark web, with the Everest ransomware threatening to dump pilot training data and Boeing's proprietary code.
The Everest ransomware gang has listed the UAE airline FlyDubai on its dark web leak site.
So far, the gang has not released any screenshots with data samples to prove its claims. However, it did post an extensive list of data points allegedly exfiltrated, which includes pilots' personal and training data.
According to the attackers, a total of around 4.36GB of exfiltrated data includes the personal information of 2,862 FlyDubai employees across 17,053 records.
The records allegedly expose data on cover pilots, cabin crew, training managers, technical pilots, dispatchers, and ground staff, and span from 2009 to 2020.
Attackers claim that the exfiltrated data includes:
- Full names
- Employee IDs
- Job titles
- Employment start and end dates
- Training completion dates and qualification check records
The attackers have set a 6-day timer for the company to negotiate – a common tactic to pressure the victim.
According to Cybernews researchers, if the data proves legitimate and is leaked, it may pose multiple risks to the company and its individuals.
“Such information could be useful for competitors. The company may face reputational damage and legal risks,” one researcher explained.
There’s also the risk of phishing and social engineering attacks.
“With such information at hand, threat actors might attempt to phish FlyDubai employees, which may lead to a breach affecting other data, including customer data,” the researcher added.
We’ve reached out to FlyDubai and will update this article once we receive a response.
FlyDubai pilot training material stolen
Apart from the personal data of the FlyDubai crew, Everest boasts of having exfiltrated a large amount of pilot training materials.
The dataset includes a full Boeing 737NG interactive training course with thousands of lesson modules with animations, audio narration, and quizzes.
The course covers every aircraft system from engines to autopilot, navigation, emergency equipment, fire protection, and landing gear.
The dataset also includes recurring training presentations on critical topics such as:
- How to inspect an aircraft before departure
- Flying over oceans (ETOPS long-range operations)
- Winter flying – de-icing, frozen runways, cold weather hazards
- Landing in fog and low visibility
- Takeoff and landing performance calculations
- Weather radar interpretation – detecting hail, turbulence, windshear
- Using iPads and electronic flight bags in the cockpit
- Navigating into challenging airports (e.g., Kathmandu with mountainous terrain)
- Dangerous goods awareness
- Baggage weight and loading procedures
- TCAS collision-avoidance system updates
The dataset also allegedly includes numbered operational directives covering policy changes, such as:
- When pilots can or cannot land on icy runways
- How to set altimeters correctly
- How to handle de-icing fluid procedures
- Baggage reconciliation problems at Dubai airport
Boeing's source code allegedly stolen
Everest claims to have a complete installation package for Boeing's Performance Engineers Tool (PET 3.2) on hand. The software calculates takeoff weights, landing distances, fuel planning, obstacle clearance, and engine-out scenarios.
The dataset allegedly includes 2,827 Java source code files – the actual programming code that runs the software. Just over 2,000 of those files are marked "Boeing Proprietary, Confidential, and/or Trade Secret."
Files also include database templates for airport and runway data. The release notes list 10 known software bugs, including incorrect unit conversions when mixing weight/fuel units, airport data being overwritten despite a "preserve" setting, and calculations failing silently after data imports.
Check if your data was exposed
Find out if your email and related personal information have appeared in known data breaches.
Everest also lists confidential manufacturer documents – a 190-page CFM engine manual marked "Proprietary Information, disclosed in confidence," and an Airbus ETOPS guide also marked as confidential.
Two complete editions of the Lido General Reference (2,300+ and 2,600+ pages each) covering global meteorology, airspace rules, communications, and country-specific flying information are also claimed to be in the dataset.
Who is Everest ransomware?
Everest is a Russia-linked group that operates as ransomware-as-a-service (RaaS), meaning it rents out its networks to other threat actors. The operation has been active since at least 2020.
Attackers perform double extortion when the victim is pressured to pay to regain access to their systems and to prevent stolen data from being leaked.
The gang is also taking ground as an initial access broker, meaning it sells network footholds to other threat actors when direct extortion doesn't pay.
In 2025, Everest ransomware claimed an attack on Coca-Cola’s Middle East distributor. The attackers claimed they had stolen data of nearly 1000 employees, as well as confidential internal documents.
Later, the gang publicly released Coca-Cola’s data, potentially indicating that ransomware negotiations had failed. According to a Cybernews investigation, the released files included passport scans, visa copies, and employee IDs in the Middle East.
The gang is also behind a breach at Collins Aerospace, which caused the avalanche of chaos across European airports.
This year, Everest targeted 2 of America's most prominent financial institutions – Frost Bank and Citizens Bank.