
The aviation agency of the United Nations said it is investigating claims of a network intrusion after a threat actor claimed that they infiltrated its network and stole confidential data.
The International Civil Aviation Organisation (ICAO) is a specialised agency of the United Nations, coordinating the principles and techniques of international air navigation, and fostering the planning and development of international air transport to ensure safe and orderly growth.
Recently, a threat actor said they infiltrated the internal network of ICAO and listed the agency as a victim on the dark web. According to a post shared on X, the threat actor is yet to publish the stolen data that reportedly includes the personal and professional details of about 42,000 people.
🌐 Alleged Data Leak of the International Civil Aviation Organization (ICAO)
A threat actor on a popular dark web forum claims to have leaked sensitive data from the International Civil Aviation Organization (ICAO). The breach reportedly involves 42,000 documents containing… pic.twitter.com/TnBzfVZw5u
According to reports, the stolen data includes first and last names, dates of birth, gender, marital status, country, address, zip code, phone numbers, primary and secondary emails, education, and employment information.
Acknowledging the claims of the threat actor, ICAO said in a statement shared with the media that it is actively investigating whether it suffered a data security incident.
“ICAO is actively investigating reports of a potential information security incident allegedly linked to a threat actor known for targeting international organisations. We take this matter very seriously and have implemented immediate security measures while conducting a comprehensive investigation.
“Further information will be provided once our preliminary investigation is complete,” reads the statement.
Last year, the United Nations Development Programme also experienced a data security incident that involved threat actors infiltrating its internal network and stealing confidential human resources data.
In a press release, the UN agency said that on March 27, it received a threat intelligence notification that threat actors infiltrated the local IT infrastructure in the UN City of Copenhagen and stole human resources and other confidential information.
On March 27, a relatively new threat group using the pseudonym 8base ransomware claimed responsibility for the data security incident at UNDP and listed the organisation as a victim on its data leak site.
The ransomware group claimed to be in possession of sensitive confidential information including personal data, accounting data, certificates, employment contracts, confidentiality agreements, invoices, receipts, and more.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543