LockBit listed Boeing on its site on 27 October 2023 with a deadline of 2 November. The listing was removed, then restored on 7 November with a statement that warnings had been ignored. On 10 November the operation published over 43GB of files, including system backups with the most recent timestamped 22 October.
Among the published material were backups from Citrix appliances, prompting immediate inference that the intrusion had used Citrix Bleed — CVE-2023-4966 — which we filed at 23-1010. The FBI and CISA subsequently attributed the intrusion to that vulnerability. Boeing said the incident did not affect flight safety and gave no further detail.
The Attacker Published The Forensics
We have recorded at 26-0802 that a quarter of its files establish no entry route, because the affected organisation did not say and nobody else could.
Here the route became knowable from the leak itself. The contents of a dump are chosen for their extortion value, not their evidentiary value, and the operation disclosed its own method by accident. It is the only file in this database where the actor supplied the missing field, and it is worth recording how thin the alternative was: a statement about flight safety and nothing else.
Listing, Delisting, Relisting
The sequence — publish the name, set a clock, withdraw the name, restore it — is choreography. A removed listing signals to observers that the victim may be negotiating; restoring it signals that they are not.
The audience is not only Boeing. It is every other organisation currently on the site or expecting to be, and we have recorded the same performance at 22-1024 and 22-0903, where staged release was the pressure mechanism. The leak site is a market signal about whether the operation follows through.
What "No Impact To Flight Safety" Answers
It is the right thing to say first and it is not a description of the incident. It addresses the question the public would ask of an aerospace manufacturer, and it leaves unaddressed what was taken, whose data it was, and whether anyone needs to act.
We filed this pattern of disclosure — answering the alarming question rather than the informative one — at 24-0821 and 26-0714. A statement that forecloses the worst reading while establishing nothing is a communications output, not a disclosure.
Compiled from contemporaneous reporting of the leak-site activity and subsequent federal advisories, listed below. The initial connection to CVE-2023-4966 was inference by researchers from the leak contents; the subsequent FBI and CISA attribution of the intrusion to that vulnerability is as reported. Volume figures come from the operation’s own listing and from reporting of the published files, and some outlets reported a larger figure; the lower, more widely reported number is carried. No leaked material has been accessed by this desk. Graded high. Corrections: corrections@forensicpost.com.