New ransomware gang claims Boeing and Airbus supplier breach
ID cards and aircraft wiring schemes may have been leaked.

Image by Bloomberg via Getty Images
- Storm ransomware claims it breached Star Aviation, a Kentucky supplier serving Boeing and Airbus aircraft.
- Leaked samples include technical schematics and possible employee ID cards, Cybernews researchers found.
- The exposed data could aid fraud, targeted scams, or future attacks on aviation organizations.
- Storm has claimed roughly 44 to 48 victims since it first appeared, mainly in the US.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A newcomer ransomware gang has claimed an attack on a US aviation supplier serving Boeing and Airbus.
A newly emerged ransomware gang going under the name Storm has added a Kentucky aerospace supplier to its growing list of victims.
The alleged attackers claim to have stolen the company’s internal documents. To prove their claims, they released a couple of data samples, which Cybernews researchers have investigated. The screenshots include technical schematics and potentially employees' identification cards.
Star Aviation is a small US aerospace company whose business centers on repairing and testing engine wire harnesses and electronic wire interconnect systems used in commercial aircraft.
According to Star Aviation's website, the company operates from Goshen, Kentucky, and provides wire harness inspection and repair services for Boeing and Airbus aircraft.
The company also develops specialized repairs for damaged aircraft components that can be approved by the Federal Aviation Administration (FAA), and alternative aircraft parts certified through the FAA’s Parts Manufacturer Approval (PMA) system.
Risk of fraud
The company's position in the aviation supply chain makes the alleged compromise significant. While the scope of the alleged data breach remains unknown, the attackers may have exfiltrated sensitive operational data that could affect aircraft maintenance.
Star Aviation itself describes its work as supporting aircraft reliability and operational readiness. Electrical wiring and electronic interconnect systems are integral to aircraft operation, so blueprints of such systems leaked may pose risks.
The leaked schematics may not be exploited by hackers in remote attacks on aircraft. However, they could give attackers a valuable map of systems that are normally hidden behind the aviation industry's technical and security perimeter. Such material could be combined with other intelligence to target aviation organizations.
Also, screenshots of ID cards suggest that not only businesses may be affected, but also individuals working there. Leaking identity cards puts affected people at risk of fraud and targeted social engineering attacks.
Cybernews has reached out to Star Aviation for comment. We will update this article once we receive a response.
Who is Storm ransomware?
Storm, a ransomware group first observed in August 2026, listed Star Aviation Inc. on its leak site on September 2nd.
The group has now claimed roughly 44 to 48 victims since it appeared, according to various ransomware monitoring services.
The gang’s victims span sectors including healthcare, financial services, manufacturing, technology, transportation, and government. The US accounts for the overwhelming majority of tracked victims.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.