
Hackers have leaked data allegedly stolen from Russian flag carrier Aeroflot following a major cybersecurity breach that led the airline to cancel dozens of round-trip flights.
In a statement to local media, Roskomnadzor, Russia’s Federal Service for Supervision of Communications, Information Technology, and Mass Media, denied allegations by hacker groups Silent Crow and the Belarusian Cyber-Partisans that Aeroflot’s internal network had been breached, calling the claims false.
“As of 14:00 on July 31, 2025, the information about a possible data leak from the company has not been confirmed,” the department said.
Soon after, the Belarusian hacker group Cyber Partisans published what it claimed to be travel data of Aeroflot CEO Sergei Aleksandrovsky on its Telegram channel. The leaked data contained details of over 30 flights taken between April 2024 and June 2025.
“We remind Roskompozor that they also denied the hacking of their own network by Cyberpartisans. And then hundreds of media articles, investigations and internal documents ended up online.
“Expect leaks from Aeroflot soon. In the meantime, we are publishing some of the Aeroflot flights (ticket reservations) of a certain Sergey Aleksandrovsky - rumors are that he is the CEO of some notorious airline,” reads the post.
Last week, Aeroflot said it had experienced a “technical failure” that led to the cancellation and rescheduling of several flights since Monday, including key domestic routes like Moscow, St. Petersburg, and Sochi. The airline also confirmed that some flights planned for later in the week were canceled.
Although Aeroflot described the incident as a technical failure, two pro-Ukrainian hacker groups, Silent Crow and the Belarusian Cyber-Partisans, claimed responsibility for the attack. Both groups have a history of targeting critical infrastructure in Russia and Belarus through cyber operations.
The groups claimed they had maintained access to Aeroflot’s corporate network for over a year, gradually expanding their foothold within the airline’s infrastructure. They also alleged they had exfiltrated the airline’s entire database, which included flight history, audio recordings of internal communications, surveillance footage, and data related to employee monitoring systems.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543