Qilin ransomware operators claimed to have breached Oklahoma’s Tulsa International Airport, publishing more than a dozen files as proof of data theft. Reporting citing Cybernews said analysis of 18 leaked samples included documents dated 2022–2025, such as emails containing the airport CFO’s contact details and correspondence with banking officials, employee ID copies, and a range of sensitive business records (e.g., NDAs, budgets and revenue spreadsheets, insurance files, telehealth reports, tenant databases, governance minutes, court case files, and vendor revenue sheets). Tulsa International Airport had not publicly acknowledged the incident at the time of reporting.
Separate ransomware/dark web reporting also highlighted Qilin activity targeting a South Korean public broadcaster, indicating continued operational tempo by the group across multiple sectors and geographies. The same weekly roundup additionally referenced unrelated dark web activity (including alleged sales/leaks involving a U.S. aerospace composites manufacturer and U.S. private universities), but the common thread relevant here is Qilin’s ongoing ransomware-driven data theft and leak-site pressure tactics.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC's Week 1 February 2026 ransomware roundup reported an alleged Qilin ransomware attack targeting a South Korean public broadcaster. The summary did not provide further technical or victim-response details in the referenced content.
Qilin allegedly added Oklahoma's Tulsa International Airport to its leak site and published 18 sample files said to be stolen from the airport's internal network. Analysis of the samples indicated data spanning 2022 to 2025, including emails, employee ID copies, financial documents, insurance files, tenant databases, and other sensitive records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.