August 14, 2026

Identity security in civil aviation: The attack surface hiding behind trusted access

Table of contents

A caller contacts an airline's help desk. They know an employee's name. They know enough personal information to answer verification questions. They sound convincing. The caller says they lost access and need their password reset. Perhaps they need a new MFA device enrolled too. The help desk solves the problem.

Except the caller was never the employee. This is not a hypothetical attack model. In 2025, security agencies warned that Scattered Spider had expanded its operations into aviation. Singapore's Cyber Security Agency reported that in almost all observed 2025 incidents involving the group, attackers used social engineering against help desks to compromise Microsoft Entra ID, SSO, or VDI accounts through password or MFA resets.

The FBI, CISA, and international partners have documented related techniques including credential theft, MFA bypass, SIM swapping, impersonation, account creation, and abuse of remote-access tools. That should change how aviation CISOs define their attack surface. Aircraft systems matter. Airport operational technology matters. Networks matter. But an attacker may not need to attack any of them first.

They can attack trust. And that makes aviation identity security one of the defining cybersecurity problems for civil aviation.

Aviation has built a connected ecosystem, and attackers have noticed the identities holding it together.

An airline does not operate as one security domain. Its employees use corporate applications. Airport staff access operational systems. Ground handlers interact with airline platforms. Contractors connect remotely. Contact centers use customer systems. Developers deploy cloud workloads. Applications authenticate through service accounts and API credentials.

Then there are airports, maintenance organizations, catering companies, technology providers, reservation systems, payment processors, loyalty partners, and other suppliers. Each relationship creates identities and trust. That is what makes civil aviation identity risk different from a conventional corporate IAM problem.

A compromised identity can cross business and technical boundaries because aviation operations depend on those connections. Recent attacks have made this increasingly visible. In June 2025, security researchers warned that Scattered Spider appeared to be targeting aviation and transportation organizations. WestJet and Hawaiian Airlines disclosed cyber incidents during the same period, although neither publicly attributed its incident to the group at that time.

Then Qantas disclosed an incident involving a third-party customer servicing platform used by a contact center. Approximately six million customer records were potentially affected. The lesson is larger than any one incident. Attackers have recognized that the people and organizations trusted to operate aviation can provide routes around traditional perimeter defenses.

The help desk has become part of the security perimeter.

Most security teams know employees can be phished. The harder problem is what happens when the attacker targets the process designed to help those employees recover access. Scattered Spider provides a useful example. Government advisories describe actors impersonating employees or IT staff, contacting help desks, obtaining credentials, bypassing MFA, conducting SIM swaps, and convincing personnel to enable remote access.

That attack model turns an identity recovery process into an initial-access mechanism. Consider the normal sequence: An employee loses a phone. They call support. The help desk verifies their identity. The old authenticator gets reset. A new MFA method gets registered. Every step is legitimate. The attacker only needs to defeat the identity verification step. This is why stronger MFA alone cannot solve airline credential theft.

If the recovery process lets an attacker replace the authenticator, the attacker does not need to defeat MFA cryptographically. They persuade the organization to issue them legitimate access. For aviation security teams, account recovery therefore needs to be treated as a form of privileged identity administration. Password resets, MFA resets, new device registration, privileged account recovery, and help-desk overrides should generate high-confidence security telemetry.

The identity is compromised. What happens next?

Stopping account takeover matters. Knowing what the compromised account can do matters just as much. Consider two airline employees. The first can access an HR portal and internal communications. The second can access a customer service platform, modify user accounts, query passenger information, connect to cloud applications, and reach systems shared with third parties.

Both credentials may be stolen using the same technique. The potential impact is completely different. That is where aviation identity security moves beyond authentication. Security teams need to understand effective access: every resource an identity can reach directly or indirectly through groups, roles, delegated permissions, trust relationships, and privilege-escalation paths.

A valid login is not proof that subsequent activity is safe. It only proves that the authentication system accepted the identity.

Your airline's identity perimeter extends into your suppliers.

The Qantas incident makes another aviation weakness difficult to ignore. The affected environment involved a third-party customer servicing platform connected to a contact center. This is normal in aviation. Airlines rely heavily on external companies for technology, customer support, maintenance, airport operations, ground handling, logistics, payments, and other business functions. The security consequence is third-party identity risk.

A supplier employee may receive federated access. A support provider may have privileged credentials. An application integration may use an API token. A contractor may retain remote access. Your security team can enforce strong controls for its own workforce while remaining exposed through identities managed elsewhere. This creates uncomfortable questions. Who verifies a contractor before an MFA reset?

Who removes supplier access when personnel changes? Which external identities have privileged access? Which integrations use persistent credentials? Can the SOC distinguish normal supplier activity from account takeover? A questionnaire cannot answer these questions continuously. Identity visibility can.

The identities without employees behind them may be harder to control

Human accounts are only one part of the problem. Airlines and airports depend on APIs, service accounts, cloud workloads, certificates, application identities, automation systems, integration credentials, and increasingly AI agents.

These are non-human identities. They authenticate without calling a help desk. They can also hold persistent, highly privileged access. That creates a different non-human identity security problem. A service account may survive long after the application owner changes teams. An API credential may remain valid for years. A workload identity may inherit broad cloud permissions. An integration account may connect an airline directly to a supplier environment.

Nobody needs to phish these identities if the credential itself becomes exposed. Security teams therefore need to know more than where secrets are stored. For every machine identity, they should know who owns it, what created it, what it can access, what credential it uses, where it normally authenticates, and when it should cease to exist. In a connected aviation environment, forgotten machine access can become a permanent trust relationship.

The aviation SOC needs to detect identity behavior, not just authentication failures.

This leads to another blind spot. Many identity controls focus on the login moment. Attackers focus on what comes after it. Once an attacker has a legitimate session, the activity may look superficially normal. The account exists. Authentication succeeded. MFA may even have been completed using the attacker's newly enrolled device.

Detection has to move deeper into the session. That is the role of aviation ITDR (Identity Threat Detection and Response). Suppose a contact-center identity suddenly registers a new authenticator, logs in from unfamiliar infrastructure, accesses administrative functionality, searches for privileged accounts, and begins querying resources outside its normal pattern.

No single event necessarily proves compromise. Together, they tell a story. The same principle applies to machine identities. A service account that normally reads one application database should not suddenly modify an IAM policy or access an unrelated cloud resource without scrutiny. Identity telemetry needs context: authentication, privilege, resources, behavior, ownership, and historical activity.

Aviation cybersecurity 2026 needs a different set of identity questions.

Aviation cybersecurity guidance already addresses cyber systems, operational disruption, supply chain risk, authentication, and access control. TSA's own cybersecurity terminology defines critical cyber systems by the operational disruption that could result if they were compromised. NIST's finalized SP 800-63 Revision 4 also strengthened guidance around digital identity risk, authentication, federation, and continuous evaluation.

The gap is not that regulators have forgotten identity. The problem is operational. Modern aviation identity relationships change faster than periodic governance processes can easily keep pace with. That means aviation cybersecurity in 2026 needs security teams to answer questions such as : continuously

  • Which human and machine identities can reach critical systems?
  • Which accounts have privileges they no longer use?
  • Which supplier identities can cross organizational boundaries?
  • Which MFA or credential changes indicate possible takeover?
  • Which non-human identities have unclear ownership?
  • Which identity behaviors changed after authentication?

These questions connect identity administration with threat detection.

Protect the trust layer before attackers exploit it.

The answer is not another isolated authentication product. Civil aviation needs a security model that connects identity posture, runtime activity, third-party access, and non-human identities. Identity Security Posture Management can identify excessive permissions, dormant privilege, dangerous access combinations, and indirect paths to sensitive resources.

Identity Threat Detection and Response can detect suspicious authentication attempts, MFA changes, privilege escalations, unusual resource access, and behavior inconsistent with an identity's established purpose. Non-Human Identity Governance can bring service accounts, API identities, workloads, certificates, and automation under ownership, privilege, credential, and lifecycle controls.

Supplier identity controls can expose external identities and integrations connecting airlines, airports, service providers, and other partners. Unosecur's Unified Identity Fabric brings these identity relationships into a single security model spanning identity providers, cloud, SaaS, human identities, non-human identities, and emerging AI agents.

That matters because the modern aviation attacker may never need to "hack the airport" as people traditionally imagine. They can call the help desk. Compromise a contractor. Take over an employee. Abuse an application credential. Or operate through an identity your systems already trust.

The aviation industry has spent decades becoming exceptionally good at verifying who is allowed onto an aircraft. Its next identity challenge is knowing exactly who and what are allowed into its digital systems.

‍

Ready To Secure Your Identities?

Blue cardholder with translucent card showing icons and the text 'unosecur'.
FAQs

Everything you Need to Know

Aviation identity security matters because airlines and airports depend on large networks of employees, contractors, suppliers, applications, workloads, and service accounts. Compromising a single trusted identity can expose the systems and data accessible through that identity's effective permissions.

‍

Airline credential theft can involve phishing, vishing, impersonation, MFA fatigue, SIM swapping, fake login pages, or manipulation of help-desk recovery processes. Recent government advisories on Scattered Spider specifically describe social engineering and MFA bypass techniques.

‍

Aviation ITDR applies Identity Threat Detection and Response principles to airline and airport identity environments. It monitors identity activity for signals such as unusual authentication attempts, MFA changes, privilege escalations, abnormal resource access, and suspicious behavior after login.

‍

Third-party identity risk arises because contractors, technology vendors, contact centers, ground handlers, and other suppliers may hold identities or integrations with access to airline systems. Their access can become another route into the airline environment if poorly governed or compromised.

‍

Yes. Service accounts, API credentials, workloads, and application identities can hold significant access without a human actively using them. Effective non-human identity security requires clear ownership, limited privilege, credential controls, activity monitoring, and lifecycle management.

‍

Airlines should combine phishing-resistant authentication with stronger recovery verification, effective-access analysis, supplier identity controls, machine identity governance, and continuous identity threat detection. The objective is to understand what every trusted identity can do before compromise turns that access into an attack path.

‍