US intelligence agencies have warned that civilian infrastructure, particularly airports, represents a significant vulnerability for US military mobilization in the event of conflict with China. Civilian airport operational technology (OT) systems—including baggage carousels, security scanners, reservation systems, and runway lighting—are often poorly secured and could be targeted by foreign adversaries to disrupt troop movements and logistics. The potential impact of such attacks was highlighted by a ransomware incident at Seattle-Tacoma International Airport, which affected baggage handling and related services, demonstrating the cascading effects a cyberattack on airport OT can have on national aviation operations.
Military planners are increasingly concerned that, during a crisis, adversaries could exploit these weaknesses to launch cyberattacks on interconnected IT and OT systems at transportation hubs, thereby hindering the rapid deployment of US forces. The reliance on civilian infrastructure for military logistics underscores the urgent need for improved security and resilience in airport OT environments to mitigate the risk of disruption from state-sponsored cyber threats, particularly those attributed to China.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
BankInfoSecurity and GovInfoSecurity published a report examining civilian airport operational technology as a potential soft underbelly for the U.S. military. No additional incident details, dates, or discrete underlying events are provided in the reference content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.