On July 28, Russian carrier Aeroflot announced disruptions to its information systems through its Telegram channel. The airline alerted travelers that technical issues might lead to flight delays or cancellations.
"A specialist team is currently working to reduce operational risks and restore normal service functionality as quickly as possible," the company stated.
Shortly after, the hacker collective Silent Crow, collaborating with Cyber Partisans BY, claimed responsibility for what they described as a complete breach and destruction of Aeroflot's IT infrastructure. The group alleged they had infiltrated the corporate network for nearly a year.
Their statement detailed: "We successfully extracted the entire flight history database, compromised all vital corporate systems, and gained access to employee workstations, including those of top executives."
Russia’s Prosecutor General’s Office later verified that the system failure resulted from a cyberattack. Authorities have opened a criminal case under Article 272 of the Criminal Code (unauthorized computer access) following a prosecutor’s investigation.
Msk1 reported long passenger queues at Moscow’s Sheremetyevo Airport due to the outage. Aeroflot’s press service confirmed 49 canceled flights, advising affected travelers to retrieve luggage and either request refunds or reschedule.
The Transport Ministry later announced coordination with Aeroflot and Rosaviatsia to reroute some passengers onto Rossiya and Pobeda flights.
[Update 13:17 MSK: Added Prosecutor General’s Office confirmation.] [Update 14:13 MSK: Included Transport Ministry’s response.]
