Desk live·
ForensicPost
Ransomware/Availability/File 22-0525

SpiceJet Ransomware Attempt Stranded Passengers and Halted Morning Departures

SpiceJet described an attempted ransomware attack on the night of 24 May 2022. The following morning departures stopped at Delhi and Hyderabad, and passengers sat on aircraft for hours with no explanation beyond that one.

Constructed geometry · not a chart of case data
JurisdictionIndiaGurugramthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSpiceJet
ActorUnattributed
S. Rosler10 min readConfidence: medium3 sources reviewed

SpiceJet stated that its systems faced an attempted ransomware attack late on 24 May 2022. Morning departures on 25 May were unable to leave the airline’s Indian hubs at Delhi and Hyderabad; flights were delayed and cancelled, and reporting describes hundreds of passengers stranded across airports for several hours. The airline switched out servers to recover, warned of cascading schedule effects, and deferred a quarterly earnings announcement.

"Attempted" Is Doing Work

The airline’s characterisation was an attempted attack. Aircraft did not depart, passengers were held, and a scheduled financial announcement was postponed.

The desk records the word without adopting it. An attempt that stops a national carrier’s morning departures has succeeded at everything except encryption, and we filed the same drift in disclosure language at 23-1110, where a company answered the question about flight safety and no other, and at 24-0821.

The People Who Bore It Had No Information

Passengers reported being told only that the server was down, and one described sitting aboard an aircraft for close to four hours without food.

That is what an incident looks like from outside the incident. We have argued at 24-1231 and 23-0625 that availability harm is uncounted; this file adds that the affected people are also uninformed by design, because the operational instruction to front-line staff during a live incident is to say as little as possible.

Switching Out The Servers

Recovery is described as replacing servers rather than cleaning them, which is the most expensive form of confidence and a decision organisations reach for when they cannot prove what was touched.

We have recorded the same judgement at 23-0625, where an energy company replaced desktops and laptops, at 23-0518 and at 22-0224. It is a reasonable response to uncertainty and it is also a measure of how little the responders could establish.

How we reported this

Compiled from the airline’s statements and contemporaneous reporting, listed below. No ransomware operation is named and no entry route was published — neither is asserted, and their absence is why this file is graded medium. No figure for affected passengers, flights or financial cost was published and none is carried. Passenger accounts are as reported in contemporaneous coverage. Corrections: corrections@forensicpost.com.

Sources
  1. SpiceJet airline passengers stranded after ransomware attackBleepingComputer
  2. SpiceJet: Passengers stranded as India airline hit by ransomware attackBBC News
  3. SpiceJet says faced ransomware attack, hundreds of flights impactedBusiness Standard
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary