Recommended Free Tools
Korean Air said information belonging to about 30,000 current and former employees was compromised after an attack on Korean Air Catering & Duty-Free (KC&D), a former Korean Air subsidiary that continued to supply catering services. The reported information included names and bank-account numbers. Korean Air said customer data was not affected. Public reporting linked the incident to the 2025 Oracle E-Business Suite (EBS) exploitation campaign associated with Clop, but Korean Air has not publicly provided forensic evidence proving the attacker or the precise route into KC&D’s systems.
What happened
The breach was reported in KC&D’s environment, not as a compromise of Korean Air’s passenger reservation or loyalty systems. Korean Air said it learned that information on approximately 30,000 current and former employees had been compromised. Reports identified the exposed fields as names and bank-account numbers. BleepingComputer’s account of Korean Air’s statement and Korea JoongAng Daily’s December 29, 2025 report describe the affected population and data.
Korean Air said customer information was not involved. That is the airline’s reported assessment; the public accounts do not provide an independent forensic finding about every system or record in the incident.
Why KC&D had Korean Air employee information
KC&D originated as part of Korean Air, later became a separate company, and was sold to private-equity firm Hahn & Company in 2020, according to reporting by SecurityWeek. It continued providing in-flight catering and related services to Korean Air and other airlines.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
A change in ownership does not automatically erase old data flows. A former subsidiary or continuing supplier may still hold information needed for payroll, benefits, operations, or other business processes. The public accounts do not explain precisely why KC&D retained these employee bank details or what contractual and technical controls governed them. That unanswered question makes this a third-party data-governance issue as well as a cyberattack story.
What information was reported exposed
| Information or system | What public reporting establishes |
|---|---|
| Employee names | Reported among the compromised fields. |
| Bank-account numbers | Reported among the compromised fields. |
| Passenger names, travel histories, or customer records | Korean Air said customer data was not affected; passenger-system exposure was not reported. |
| Payment-card numbers, identity documents, or government ID numbers | Not established in the cited reports. |
| Passwords or multifactor-authentication data | Not established in the cited reports. |
The absence of a field from public reporting does not prove it was absent from every stolen file. It does mean readers should not treat broader lists circulating in secondary summaries as confirmed without a company notice or other reliable evidence.
Rank #2
- Auto-Fill Feature: Say goodbye to the hassle of manually entering passwords! PasswordPocket automatically fills in your credentials with just a single click.
- Internet-Free Data Protection: Use Bluetooth as the communication medium with your device. Eliminating the need to access the internet and reducing the risk of unauthorized access.
- Military-Grade Encryption: Utilizes advanced encryption techniques to safeguard your sensitive information, providing you with enhanced privacy and security.
- Offline Account Management: Store up to 1,000 sets of account credentials in PasswordPocket.
- Support for Multiple Platforms: PasswordPocket works seamlessly across multiple platforms, including iOS and Android mobile phones and tablets.
How Oracle E-Business Suite fits in
Oracle EBS is enterprise software used for business processes such as finance, procurement, human resources, and supply-chain operations. In 2025, security reporting described a campaign exploiting Oracle EBS vulnerabilities to steal data from organizations. KC&D’s breach was publicly associated with that campaign, including in SecurityWeek’s coverage and Rescana’s technical analysis.
- Established: KC&D suffered a breach involving employee data.
- Reported: Clop listed KC&D as a victim, and reporting connected the incident to the Oracle EBS campaign.
- Not publicly established for this specific case: the exact exploited vulnerability, EBS version, initial-access path, or forensic chain linking the intrusion to a named actor.
Some security reporting also discusses FIN11 or TA505 in connection with activity attributed to Clop. Threat-intelligence labels can differ among vendors and are not interchangeable proof of who accessed KC&D’s systems. MITRE ATT&CK’s Clop entry provides group context, not case-specific forensic confirmation.
Rank #3
- NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
- ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
- ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
- THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
- PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.
What Clop claimed and what the leak figure means
SecurityWeek reported that KC&D appeared on Clop’s leak site on November 21, 2025, and that nearly 500 GB of archives allegedly taken from the company were later made public. These are claims and figures reported in connection with attacker-controlled material, not an independently audited measurement of Korean Air employee data. The reported archive volume does not mean that 500 GB consisted of the roughly 30,000 employee records.
Korean Air did not publicly provide an independent attribution to Clop in the cited reporting. The group’s claim is relevant evidence about the incident’s reported context, but it should not be presented as a definitive forensic conclusion.
Rank #4
- NEVER FORGET A PASSWORD AGAIN - Clever Fox password journal will help you create secure passwords and keep them safe and organized. This password book allows you to store all your passwords and other computer information in one place to find it easily.
- ALPHABETICAL A-Z TABS - Alphabetic tab system makes it easy to find any password you need. The book also has sections for most important passwords, wireless & email settings, software license information & additional notes.
- ELEGANT, SMART, PRACTICAL & SECURE PASSWORD ORGANIZATION - This password keeper book has been designed to be anonymous without an obvious title on the cover. For added security there is space to write hints instead of the password itself.
- POCKET SIZE & PREMIUM QUALITY - This internet address and password logbook with tabs comes in pocket size (4.0x5.5 inches). The password notebook has an eco-leahter hardcover, elastic band, pen loop, bookmark, pocket for notes, and thick 120gsm paper.
- 60-DAY MONEY-BACK GUARANTEE - We will exchange or refund your password organizer if you aren’t satisfied with your password organization for any reason. Reach out to us via message to refund your internet password logbook.
Timeline
- 2020: KC&D was separated from Korean Air and sold to private-equity ownership, according to reporting.
- November 21, 2025: SecurityWeek reported KC&D’s appearance on Clop’s leak site.
- December 29, 2025: Korean Air’s disclosure was reported by Korea JoongAng Daily and BleepingComputer.
- December 30, 2025: SecurityWeek published its report on the incident and Oracle EBS connection.
What affected employees can do
Names paired with bank-account numbers can make convincing payroll, banking, or HR impersonation attempts easier. The reporting does not establish that account access, identity theft, or financial loss occurred. Practical steps can reduce the chance that a deceptive message turns into a loss:
- Verify payroll requests independently. Treat unexpected messages asking you to confirm bank details or change direct deposit as suspicious. Contact HR or payroll using a known company channel, not contact details in the message.
- Watch bank activity and deposits. Review account alerts, transactions, and expected payroll deposits. Ask your bank whether transaction alerts or additional controls are appropriate for your situation.
- Ask the employer specific questions. Through an established internal channel, ask whether account numbers were readable, whether credentials or authentication data were involved, what notification and support are available, and whom to contact about suspected fraud.
- Do not seek out alleged stolen files. Downloading or searching breach archives can expose you to malicious files and further circulate personal information.
- Match protection to confirmed exposure. The cited reporting does not establish that identity documents or government ID numbers were exposed. If an official notice identifies additional sensitive data, follow its jurisdiction-specific guidance and ask your bank or relevant authorities what protections apply.
What companies should examine after a divestiture
For Korean Air, KC&D, and other organizations with former-subsidiary or supplier relationships, the key control question is not only whether an application was patched. It is also whether sensitive data still needs to be in that environment and whether the relationship is governed and monitored as a current third-party risk.
Best Value
- Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More
- Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
- Enter one PIN number and have access to 400 accounts. Search function included.
- Unit auto locks for 30 minutes after 5 consecutive incorrect PIN attempts
- Includes mini stylus for easier keypad entry
- Inventory data held by suppliers and former subsidiaries, including the business purpose and retention period for each category.
- Review data-processing agreements, deletion obligations, breach-notification deadlines, audit rights, and responsibilities for employee notices.
- Minimize access and retention; where appropriate, mask, tokenize, or encrypt bank information, and restrict who can retrieve it.
- For Oracle EBS operators, review internet exposure, security updates and mitigations, service-account privileges, network segmentation, and monitoring for unusual access or outbound data transfers.
- Include suppliers in incident exercises and access reviews, and reassess inherited integrations when ownership or business arrangements change.
These are risk-management measures, not evidence that a particular control failed at KC&D. Public reporting does not establish the affected Oracle version, exact exploit path, duration of attacker access, whether a ransom was paid, or whether operations were disrupted.
Separate incident at Asiana Airlines
Asiana Airlines separately reported around the same period that information relating to approximately 10,000 employees might have been stolen. SecurityWeek said there was no indication that the Asiana incident was connected to the Oracle EBS campaign. Its timing is not evidence of a coordinated attack on Korean aviation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




