October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Hawaiian Airlines Cyberattack: What Happened and What Scattered Spider Warnings Mean

Hawaiian Airlines suffered a contained cybersecurity incident in June 2025. Flights continued safely, systems were later restored, and Scattered Spider was suspected but not publicly confirmed as responsible.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hawaiian Airlines disclosed a cybersecurity incident affecting certain information-technology systems in June 2025. The airline said flights continued safely and as scheduled. Later, Alaska Air Group reported that affected systems had been restored and that the incident did not materially affect Hawaiian’s business, results of operations, or financial condition.

Incident responders and security researchers suspected a connection to Scattered Spider, also known as UNC3944, but Hawaiian Airlines did not publicly confirm that attribution. There is also no publicly confirmed disclosure in the cited materials that passenger data was stolen, that ransomware was deployed, or that aircraft or flight-control systems were compromised.

What happened to Hawaiian Airlines?

Hawaiian Airlines identified a cybersecurity incident on June 23, 2025, affecting certain IT systems. The airline publicly acknowledged the incident on June 26, and its parent company, Alaska Air Group, filed a report with the U.S. Securities and Exchange Commission on June 27.

In that filing, Alaska Air Group said Hawaiian had engaged authorities and outside experts, while flights continued to operate safely and as scheduled. The filing did not identify the specific systems involved, the initial access method, the data potentially accessed, or the malware used.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The later outcome was more reassuring than the initial breaking-news coverage suggested: Alaska Air Group’s 2025 annual report said the affected systems were restored, flights were not interrupted during the response, and the incident did not have a material impact on Hawaiian’s business, results of operations, or financial condition.

Timeline of the incident

  • June 23, 2025: Hawaiian identified a cybersecurity incident affecting certain IT systems.
  • June 26, 2025: The airline publicly disclosed the incident and said it was working toward restoration.
  • June 27, 2025: Alaska Air Group filed an SEC Form 8-K describing the event.
  • June 27–30, 2025: Federal agencies, Mandiant, and Palo Alto Networks warned that Scattered Spider activity had expanded into aviation and transportation.
  • Later disclosure: Alaska Air Group reported that systems had been restored and that the incident had no material impact on the company’s financial condition.

Was Scattered Spider responsible?

That has not been publicly confirmed. Contemporary reporting quoted incident responders who believed the incident was likely connected to Scattered Spider. Mandiant said multiple aviation incidents resembled the group’s operations, while cautioning that attribution and analysis were still ongoing.

Scattered Spider is also tracked by some security organizations as UNC3944. Different researchers and law-enforcement agencies may use different names for overlapping activity, but a similar pattern does not by itself prove that every aviation incident came from the same operation.

The most accurate description is that the Hawaiian incident was suspected to be linked to Scattered Spider. Hawaiian Airlines did not publicly attribute the attack to the group in the company disclosures cited here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What systems were affected?

Public filings disclosed only that “certain IT systems” were affected. They did not specify whether the incident involved reservations, crew scheduling, loyalty programs, payments, employee records, airport operations, or a third-party provider.

That distinction matters. The available evidence does not establish compromise of:

  • Passenger reservation systems;
  • Flight-dispatch systems;
  • Crew-scheduling platforms;
  • Airport operational technology;
  • Loyalty-program or payment systems;
  • Aircraft systems or flight controls; or
  • Passenger or employee databases.

“IT systems” is too broad a phrase to support conclusions about aircraft safety or passenger-data theft.

Were Hawaiian Airlines flights affected?

According to the company’s disclosures, flights continued safely and as scheduled. The later annual report also said flights were not interrupted during the response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That does not prove every airline system was unaffected. It does mean the available company statements do not support claims that the incident caused a flight-control breach, canceled flights, or a safety-of-flight crisis.

Airlines operate several overlapping technology environments. Corporate and customer-facing systems can be compromised without evidence that safety-critical aircraft systems were breached. Those categories should not be treated as interchangeable.

Was passenger data stolen?

No public source cited for this incident establishes that Hawaiian passenger data was stolen, exposed, or sold. The initial disclosures did not provide a detailed forensic account of data access, and the later annual-report statement about no material financial impact was not a declaration that no data or systems were affected.

The narrow, supportable conclusion is: passenger-data theft was not publicly confirmed in the reviewed materials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was this a ransomware attack?

Ransomware was not publicly confirmed in Hawaiian’s SEC filing or Alaska Air Group’s later annual report. Some secondary reporting or threat-intelligence descriptions may characterize the event as involving disruption, extortion, or ransomware, but those descriptions should not be presented as established company-confirmed facts.

Scattered Spider has been associated with data theft, extortion, and ransomware in other campaigns. That broader pattern does not prove ransomware was deployed against Hawaiian Airlines.

How Scattered Spider-style attacks work

The group’s reported approach often relies less on exploiting a single software flaw and more on manipulating people and identity processes. Common targets include help desks, contractors, outsourced service providers, and administrators with access to cloud applications.

An attacker may try to:

  • Impersonate an employee or contractor;
  • Persuade a help-desk worker to reset a password or multifactor-authentication method;
  • Exploit weak identity-verification procedures;
  • Abuse valid credentials after gaining access;
  • Move from an identity platform into business applications;
  • Target a trusted vendor or managed-service provider; or
  • Steal data and demand payment or deploy ransomware in some campaigns.

The FBI’s joint advisory with CISA and international partners provides technical information on Scattered Spider activity based on investigations through June 2025. It is useful context, but it does not publicly prove that every technique described was used against Hawaiian.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why airlines are attractive targets

Airlines combine high-value data, complex operations, numerous vendors, and intense pressure to restore service. Their technology environments may include reservation systems, loyalty accounts, payment processing, employee systems, airport operations, contractors, call centers, and managed-service providers.

That creates an unusually broad identity and access-management problem. A support employee at an outsourced call center, a contractor with administrative permissions, or a help-desk agent authorized to reset credentials can become a high-value target.

The practical risk is therefore not limited to malware or unpatched software. A convincing social-engineering attempt can undermine a weak account-recovery process even when the organization has modern security products elsewhere in its environment.

What the aviation warnings meant

The FBI said it had observed Scattered Spider expanding its targeting to airlines and encouraged aviation organizations to report suspicious activity quickly. Mandiant reported seeing multiple airline and transportation incidents resembling UNC3944 operations, while Palo Alto Networks also reported activity targeting aviation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These warnings should not be read as confirmation that all aviation incidents in that period were connected. They did signal that airlines and their trusted partners should treat identity attacks, help-desk impersonation, and vendor access as sector-wide risks.

What happened afterward?

Alaska Air Group’s 2025 annual report provides the most important later update:

  • The affected systems were restored.
  • Flights were not interrupted during the response.
  • The company used established response protocols and compensating controls.
  • The incident did not materially affect Hawaiian’s business, results of operations, or financial condition.

“No material impact” is not the same as “no impact.” It is a financial-reporting conclusion and does not establish that no users, systems, or data were affected.

What remains unknown?

The public disclosures do not establish:

  • The initial access vector;
  • The specific applications or network segments affected;
  • Whether data was exfiltrated;
  • Whether passenger or employee records were accessed;
  • Whether ransomware was deployed;
  • Whether a vendor or contractor was involved; or
  • Whether Scattered Spider was definitively responsible.

Those gaps are important because a cybersecurity incident, a data breach, a ransomware attack, and an aircraft-systems compromise are different events. The available evidence supports only the first description with certainty.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Lessons for airlines and other companies

Use phishing-resistant multifactor authentication

Security keys and passkeys based on phishing-resistant standards provide stronger protection than SMS codes and many ordinary one-time-password workflows. They should be prioritized for administrators, help-desk staff, identity teams, and other employees who can reset credentials or change access permissions.

Deployment can be difficult for hourly workers, remote stations, contractors, shared devices, legacy applications, and emergency-access workflows. Organizations should plan enrollment, replacement, offline access, and recovery before enforcing stronger authentication. Eliminating fallback methods without a tested recovery process can create operational lockouts.

Strengthen help-desk identity verification

Help desks should not rely solely on information an attacker can find or obtain elsewhere. Verification should use procedures resistant to impersonation, with additional scrutiny for password resets, MFA changes, privileged accounts, and unusual geographic or device patterns.

Limit privileged access

Administrative accounts should be separated from ordinary user accounts, granted only the permissions required for the job, and monitored for unusual changes. Short-lived access and approval workflows can reduce the damage from a compromised administrator or contractor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control vendor and contractor access

Organizations should inventory third-party accounts, require strong authentication, limit access by role and time, and remove access promptly when a contract or assignment ends. Outsourcing a help desk or technology function does not outsource the organization’s responsibility for identity security.

Monitor identity changes

Security teams should alert on suspicious password resets, MFA-device enrollments, privilege changes, impossible-travel patterns, unusual cloud logins, and access from unfamiliar devices. Identity telemetry can reveal an intrusion even when endpoint malware is absent.

Test incident response

Airlines and other critical businesses need response plans that cover account takeover, vendor compromise, customer-service disruption, data theft, and operational continuity. Exercises should include communications, legal and regulatory reporting, law-enforcement contact, backup access, and manual workarounds.

What this means for passengers and consumers

There is no cited public confirmation that Hawaiian passenger data was stolen. Passengers should nevertheless use ordinary account-security precautions: avoid reusing passwords, enable the strongest available multifactor authentication, monitor loyalty and payment accounts, and treat unexpected password-reset messages or support calls as suspicious.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Consumers should not assume that a cybersecurity incident automatically means their identity or payment information was exposed. At the same time, the absence of a disclosed data breach is not proof that no information was accessed. The appropriate response is to rely on official notices and monitor relevant accounts without treating speculation as fact.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.