Reporting counted at least ten major cyberattacks against airlines and airports during 2025, and analysis of the 2026 landscape describes aviation and aerospace as a sustained target across carriers, airports, maintenance organisations and suppliers.
Two Regulatory Cultures In One Industry
Aviation has the most developed safety culture of any commercial sector. Incidents are investigated by independent bodies, findings are published, and the industry treats a near miss at one operator as everyone’s lesson.
None of that machinery applies to a cyber incident. There is no equivalent investigator, no mandatory published finding, and no expectation that an airline will tell its competitors how it was compromised. The industry that pioneered blameless incident analysis handles this category with commercial confidentiality.
The Distinction That Permits It
The defensible reason is that almost all of these incidents affect business systems rather than flight safety systems, and the separation between those is genuine and enforced.
That is a real distinction, and it explains why passengers have been delayed rather than endangered. It also means the most disruptive incidents in the sector fall outside the framework the sector is best at.
Passenger Data Is The Quieter Exposure
Alongside operational disruption sits the data question this desk filed at Qantas in 26-0702: carriers hold identity documents, travel patterns and frequent-flyer histories, and the 2026 escalation showed that a 2025 theft can surface as a publication a year later.
Graded medium. Incident counts vary by source and counting rule; we treat the concentration as the finding rather than the number.
This is a sector analysis file built on published research and reporting, listed below. Counts differ between sources according to what qualifies as a major incident. Corrections: corrections@forensicpost.com.