Desk live·
ForensicPost
Ransomware/Aftermath/File 23-1110

LockBit Published 43GB From Boeing, Revealing the Citrix Bleed Entry Route

LockBit listed Boeing, set a deadline, removed the listing, restored it, then published 43GB. Among the files were Citrix appliance backups — which is how anyone reading the leak could work out how the intruders got in.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBoeing
ActorLockBit
S. Rosler11 min readConfidence: high3 sources reviewed

LockBit listed Boeing on its site on 27 October 2023 with a deadline of 2 November. The listing was removed, then restored on 7 November with a statement that warnings had been ignored. On 10 November the operation published over 43GB of files, including system backups with the most recent timestamped 22 October.

Among the published material were backups from Citrix appliances, prompting immediate inference that the intrusion had used Citrix Bleed — CVE-2023-4966 — which we filed at 23-1010. The FBI and CISA subsequently attributed the intrusion to that vulnerability. Boeing said the incident did not affect flight safety and gave no further detail.

The Attacker Published The Forensics

We have recorded at 26-0802 that a quarter of its files establish no entry route, because the affected organisation did not say and nobody else could.

Here the route became knowable from the leak itself. The contents of a dump are chosen for their extortion value, not their evidentiary value, and the operation disclosed its own method by accident. It is the only file in this database where the actor supplied the missing field, and it is worth recording how thin the alternative was: a statement about flight safety and nothing else.

Listing, Delisting, Relisting

The sequence — publish the name, set a clock, withdraw the name, restore it — is choreography. A removed listing signals to observers that the victim may be negotiating; restoring it signals that they are not.

The audience is not only Boeing. It is every other organisation currently on the site or expecting to be, and we have recorded the same performance at 22-1024 and 22-0903, where staged release was the pressure mechanism. The leak site is a market signal about whether the operation follows through.

What "No Impact To Flight Safety" Answers

It is the right thing to say first and it is not a description of the incident. It addresses the question the public would ask of an aerospace manufacturer, and it leaves unaddressed what was taken, whose data it was, and whether anyone needs to act.

We filed this pattern of disclosure — answering the alarming question rather than the informative one — at 24-0821 and 26-0714. A statement that forecloses the worst reading while establishing nothing is a communications output, not a disclosure.

How we reported this

Compiled from contemporaneous reporting of the leak-site activity and subsequent federal advisories, listed below. The initial connection to CVE-2023-4966 was inference by researchers from the leak contents; the subsequent FBI and CISA attribution of the intrusion to that vulnerability is as reported. Volume figures come from the operation’s own listing and from reporting of the published files, and some outlets reported a larger figure; the lower, more widely reported number is carried. No leaked material has been accessed by this desk. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. LockBit ransomware leaks gigabytes of Boeing dataBleepingComputer
  2. Boeing investigating leaked data after LockBit allegedly publishes stolen infoThe Record
  3. LockBit hackers publish 43GB of stolen Boeing dataCS Hub
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary