Desk live·
ForensicPost
Ransomware/Aftermath/File 22-1111

Daixin Took Data on 5 Million AirAsia Passengers and Every Employee

Daixin took data on five million AirAsia passengers and every employee in November 2022. The employee records reportedly included secret questions alongside their answers — the recovery mechanism for every other account those people hold.

Constructed geometry · not a chart of case data
JurisdictionMalaysiaKuala Lumpurthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAirAsia Group
ActorDaixin Team
S. Rosler11 min readConfidence: medium3 sources reviewed

The Daixin Team claimed a ransomware attack on AirAsia Group on 11 and 12 November 2022, reporting data on five million passengers and all employees. Reporting describes a passenger file containing passenger identifiers, full names and booking identifiers, and an employee file containing photographs, secret questions, secret answers, birth city, birth state, birth country and nationality.

Reporting indicates the airline engaged with the group, received a sample, and did not pursue negotiation further. The group subsequently said it had abandoned deeper attacks on the network, attributing this to the disorganised state of the airline’s internal configuration.

A Secret Answer Cannot Be Rotated

The passenger data is ordinary — names and booking references, unpleasant to lose and bounded in what it enables. The employee file is not.

Security questions and their answers are the fallback path into accounts everywhere else: the bank, the email provider, the government portal. The answers are facts about a person’s life, they were true before the employer collected them, and they remain true afterwards. We filed unresettable identifiers at 26-0726 and 22-0922, and this is that category arriving through an employer rather than a service.

Birth City, Birth State, Birth Country

Those three fields, reported together with the security answers, are the classic question set themselves — mother’s home town, place of birth, first school.

An organisation that stores both the questions and the answers has built a lookup table for the recovery flows of every other service its staff use. We have recorded employee data as the consistent and least-considered casualty at 23-1219 and 23-0808, and this is the sharpest instance: the staff had no choice about providing it and no way to invalidate it afterwards.

Disorder Is Not A Control

The group’s reported comment — that the network was too chaotic to be worth exploring further — is an attacker’s claim, offered by a party with reasons to be dismissive, and the desk records it as that.

It is worth recording because it inverts everything else in this database, where clarity of architecture is the thing that limits damage: the isolated system at 23-0217, the ministries kept off the shared platform at 23-0724. If disorganisation deterred anything here it did so after five million records had already gone, which makes it an outcome rather than a defence.

How we reported this

Compiled from contemporaneous reporting of the group’s claims and of the airline’s response, listed below. The airline did not publish a figure for affected individuals or a breakdown of categories that this desk could use to corroborate them. The group’s remarks about the state of the network are an attacker claim and are recorded as such, not adopted. No sample or file listing has been accessed by this desk. Corrections: corrections@forensicpost.com.

Sources
  1. Daixin Ransomware Gang Steals 5 Million AirAsia Passengers’ and Employees’ DataThe Hacker News
  2. AirAsia allegedly hit with ransomware attack, data of five million passengers and employees reportedly compromisedThe Star
  3. Daixin Ransomware Gang Abandons Hack of AirAsia due to Airline’s "Chaotic Network Standards"Bitdefender
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary