Korean Air has confirmed a data breach impacting thousands of its employees after its in-flight catering and duty-free supplier, Korean Air Catering & Duty-Free (KC&D), suffered a cyberattack. The breach resulted in the exposure of personal information, including names and bank account numbers, stored in KC&D's ERP system. KC&D, which was spun off from Korean Air in 2020, notified the airline of the incident, prompting Korean Air to issue an internal notice and report the breach to authorities. Local reports estimate that approximately 30,000 employee records were compromised, though there is no evidence yet that the stolen data has been used for fraudulent purposes.
Korean Air has advised its staff to remain vigilant for phishing attempts or fraudulent communications that may impersonate the company or financial institutions. The airline emphasized that the breach was limited to employee data and that no customer information was affected. Efforts are ongoing to determine the full scope of the leak and to prevent potential secondary damage, with employees urged to exercise caution regarding suspicious requests for financial or security information.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
On December 29, 2025, Korean Air disclosed the breach, said customer data and flight operations were not affected, and warned employees to watch for phishing and other misuse of their information. The airline also reported the incident to authorities, launched an investigation, implemented emergency security measures, reviewed partner security, and in one report severed digital ties with KC&D.
After the intrusion, the Clop ransomware gang publicly claimed responsibility for the KC&D breach and published stolen data on its leak site. One report says nearly 456 GB of data was leaked after ransom demands were not met.
Korean Air Catering & Duty-Free (KC&D), a supplier and former subsidiary of Korean Air, was compromised through its ERP environment, leading to the theft of personal data tied to Korean Air employees. The exposed information included names and bank account numbers, and reports say about 30,000 current and former employees were affected.
During 2025, the Clop ransomware group conducted a broader campaign exploiting the Oracle E-Business Suite zero-day CVE-2025-61882 to gain access to victim environments and steal data. Multiple references describe the Korean Air-related breach as part of this wider activity targeting supply chains and high-profile organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.