30th July 2025 Cyber Update: Russian Airline Grounded by Pro-Ukraine Hackers and Ohio Health System Hit by Interlock Ransomware

Russia's Aeroflot airline cancels 40+ flights after Silent Crow hackers claim year-long infiltration. Meanwhile, Ohio's Kettering Health confirms Interlock ransomware attack exposed patient data including Social Security numbers and medical records.

30th July 2025 Cyber Update: Russian Airline Grounded by Pro-Ukraine Hackers and Ohio Health System Hit by Interlock Ransomware
Photo by Artturi Jalli / Unsplash

Cyber News Centre's cyber update for 30th July 2025: Russia's flagship airline Aeroflot has been forced to cancel over 40 flights after pro-Ukrainian hackers claimed a devastating year-long infiltration of its systems. Meanwhile, Ohio's Kettering Health has confirmed a major ransomware attack by the Interlock group that exposed sensitive patient data including Social Security numbers and medical records.

1. Russian Airline Aeroflot Crippled by Pro-Ukraine Cyberattack

Aeroflot is Russia's largest airline and the country's flag carrier, operating domestic and international flights from its main hub at Moscow's Sheremetyevo Airport.

The Update and Why It Matters

Update: Pro-Ukrainian hacker group Silent Crow, working with Belarusian cyber-activists Cyber Partisans BY, claimed responsibility for a devastating cyberattack that forced Aeroflot to cancel more than 40 flights on July 28, 2025. The hackers alleged they had infiltrated Aeroflot's network for over a year, compromising more than 7,000 servers and destroying core IT infrastructure including SAP management systems, staff scheduling platforms, and communications networks.

Russian prosecutors confirmed the attack and launched a criminal investigation, while hundreds of passengers were stranded at Moscow's Sheremetyevo Airport without refunds or rebooking assistance as ticket counters and online systems remained offline.

Why it Matters: This attack represents a significant escalation in cyber warfare tactics targeting civilian aviation infrastructure, demonstrating how geopolitical conflicts now extend into digital battlegrounds that directly impact public safety and economic stability. The incident exposes critical vulnerabilities in airline cybersecurity protocols and highlights the growing threat to global aviation networks, particularly as travel rebounds post-pandemic.

For Australian travelers and businesses, this underscores the urgent need for enhanced cybersecurity measures across all critical infrastructure sectors, as similar attacks could disrupt international travel routes and supply chains that Australia depends on for trade and tourism.


2. Ohio's Kettering Health Confirms Interlock Ransomware Attack Exposing Patient Data

Kettering Health is a major 14-hospital healthcare system based in Ohio. The organization provides comprehensive medical services including emergency care, specialized treatments, and outpatient services to hundreds of thousands of patients.

The Update and Why It Matters

Update: Kettering Health confirmed in a July 2025 notice that patient data was breached in a ransomware attack by the Interlock group between April 9 and May 20, 2025. The healthcare system took its IT systems offline on May 20 after discovering the breach, during which unauthorized parties viewed or stole certain files and folders. The compromised data potentially included patient names, dates of birth, Social Security numbers, driver's license numbers, medical diagnoses, treatment information, and financial account details.

US federal agencies including the FBI, CISA, Department of Health and Human Services, and MS-ISAC issued a joint warning about Interlock's escalating attacks on healthcare providers, noting the group's double-extortion tactics that involve both encrypting systems and stealing data for publication threats.

Why it Matters: This attack highlights the critical vulnerability of healthcare systems to ransomware operations that can disrupt patient care and expose highly sensitive medical information. The Interlock group's targeting of healthcare providers represents a direct threat to patient safety and privacy, with potential consequences including delayed treatments, compromised medical records, and identity theft risks for hundreds of thousands of patients.

For Australian healthcare organizations, this incident underscores the urgent need for enhanced cybersecurity protocols, regular system backups, and incident response planning, as similar attacks could cripple medical services and expose patient data across the country's healthcare networks.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.