Envoy Air, the largest carrier operating under American Airlines, confirmed on 17 October 2025 that it was affected by the wave of attacks exploiting the Oracle EBS zero-day filed at 25-0930.
Subsidiaries Run Their Own Estates
A regional carrier within a major airline group typically operates its own back-office systems. That is a deliberate structure — separate operating certificates, separate labour arrangements, separate financials — and it means the parent’s security programme does not automatically extend to it.
From an attacker’s position that is an advantage. A subsidiary carries the parent’s brand association and data relationships while frequently running with a fraction of the parent’s security capability.
Aviation Appears Again Through The Back Office
This desk has now filed aviation through operational disruption at 25-0919 and 26-0406, through customer data at 26-0702 and 26-0327, and here through enterprise administration.
None of these touched flight-safety systems, and the separation between safety-critical and business systems in aviation is genuine and enforced. It is worth restating each time, because it is the reason a sector this heavily targeted has produced delays rather than danger.
Compiled from public reporting, listed below. The scope of affected data has not been established publicly. See 25-0930 for the campaign. Corrections: corrections@forensicpost.com.