A suspected cyberattack on Vienna Airport has sparked a debate about the IT security of critical infrastructure and the methods of international extortion gangs. The cybercriminal group Bashe claims to have stolen sensitive data from Austria's largest airport and is threatening to publish it on the dark web. As alleged proof, the group published cargo documents from 2025, which, among other things, document the transport of firearms and chemicals.
The airport's operating company immediately rejected claims of an imminent threat, dismissing the reports as outdated and irrelevant. Regular flight and handling operations were unaffected, and the company stated there was no evidence of any leakage of personal or business-critical customer data. This incident is the latest in a series of global cybersecurity incidents in the logistics and transportation sector, highlighting the increasingly aggressive marketing strategies employed by modern ransomware actors.
The details of the published cargo documents and the reaction of the airport management
The data extracts presented by the attackers as proof of authenticity include so-called pre-flight reports and detailed loading lists from transport flights. A document from flight TP1271 from Vienna to Portugal attracted particular attention, revealing the transport of Glock pistols with a total weight of 1590 kilograms. Since these weapons have been adopted as standard service weapons by the Portuguese armed forces, this constitutes a legal arms shipment; however, the logistical details are typically subject to strict secrecy regulations. Another published document details the transport of hazardous chemical goods on the same flight route in April 2025.
Vienna Airport spokesperson Peter Kleemann emphasized in an official statement that the documents found online were outdated fragments whose publication posed no operational risks. The widespread encryption of IT systems typical of ransomware attacks, which could lead to massive disruptions in terminal management or baggage handling, never occurred. To fully investigate the incident, the airport's internal IT department, in cooperation with the relevant state security authorities and external cybersecurity service providers, has initiated forensic analyses. Management has ruled out direct negotiations with the extortionists or ransom payments in cryptocurrencies such as Bitcoin.
The business model of double extortion and the technical similarity to Lockbit
The group suspected of carrying out the attack operates under the name Bashe, but is also known in IT circles as APT73 or Eraleig. This criminal organization employs the principle of so-called double extortion. With this method, the perpetrators not only attempt to demand ransom for system restoration by encrypting servers, but also copy sensitive data beforehand in order to exert additional financial pressure by threatening to publish it. In this particular case, the group set a deadline of five days and simultaneously offered to remove individual employee records from the overall damage report for a separate fee.
Security analysts investigating Bashe's darknet presence have documented striking parallels to the notorious Lockbit malware. The menu structures, design elements, and organizational processes on Bashe's ransomware platform are virtually identical to Lockbit's systems. For years, Lockbit was considered one of the world's most active groups in the ransomware-as-a-service sector, where the actual malware is rented out to subcontractors. Following a coordinated international police operation in the spring of 2024, which dismantled significant parts of Lockbit's infrastructure, many of the programmers and network partners involved regrouped. Experts therefore assume that Bashe is a direct offshoot or successor project of former Lockbit actors.
Geographical allocation and strategic target selection in the industrial sector
Identifying the exact perpetrators is extremely complex due to obfuscation tactics such as the use of proxy servers, VPN services, and anonymous cryptocurrencies. The timing of the Lockbit takedown and the first appearance of Bashe suggests, according to analyses by IT security firms, an origin in the Russian-speaking world or within the Commonwealth of Independent States. In these regions, state authorities often tolerate cybercriminal activities as long as the attacks are directed exclusively against targets in Western industrialized nations.
Statistical analyses of threat reports by the IT security company SOCRadar show that Bashe's attacks primarily target countries with strong economies. Most documented incidents affect companies in the UK, the US, Brazil, and Switzerland, followed by targeted attacks in Germany and Austria. The group deliberately focuses on sectors where data breaches and potential business disruptions can cause maximum financial damage. Besides large logistics and transport companies, healthcare facilities and international financial service providers are among the network's primary targets.
Between bluff and professionalization: The phenomenon of criminal marketing
A striking characteristic of Bashe is its pronounced need for self-promotion, reflected, among other things, in its use of the alias APT73. The term Advanced Persistent Threat (APT) is typically reserved in IT security architecture exclusively for highly specialized, often state-sponsored or military-funded hacking groups from countries like China, Russia, or North Korea. Analysts at threat research firms like CloudSEK consider the fact that a primarily financially motivated ransomware gang is claiming this nomenclature for itself to be a pure marketing ploy to enhance its reputation within the cybercriminal underworld.
Investigations show that a significant portion of the hacks claimed by Bashe are based on deception. The group tends to purchase or copy older datasets from past attacks by other hackers, then declare them as recent intrusions into highly secured networks. Their claim to possess comprehensive, up-to-date government data from South America is also strongly doubted by experts. Despite these signs of structural inexperience and strategic bluffing, cybersecurity experts warn against underestimating the group. Its rapid growth potential and access to established malware code represent a continuous threat to corporate networks, necessitating ongoing adaptation of defensive security architectures in both the private and public sectors.