Russian state-backed group Energetic Bear hacked into San Francisco airport Wi-Fi systems
Russian state-backed hacking group Energetic Bear, also known as Dragonfly, hacked into the San Francisco International Airport (SFO) Wi-Fi systems and two SFO-operated websites starting March 17, 2020, according to cybersecurity firm ESET. Officials believe that the group was searching for one specific, unidentified traveler. Hackers injected code into two Wi-Fi portals that stole usernames to “fingerprint” visitors, and upon detecting a device using an older version of Internet Explorer, they would infect the laptop. Only ten devices were impacted, and the hundreds of thousands of devices that used other browsers were left alone. After about two weeks, officials at two other West Coast airports had also discovered that they had been compromised.

About This Incident

Threat Actors: Russia

Incident Metadata

Date: 4/1/2020
Country: United States
Source: Source Source 2