DBHunter
Infinity Member
Golden Member
- Joined
- August 23, 2025
- Messages
- 2,358
- Reaction score
- 5,309
- Points
- 113
- Thread Author
- #1
Hello DNA.
Today I am releasing the complete data extraction from Complete Aircraft Group (completeaircraftgroup.com) – a UK-based global aviation services, parts, and maintenance provider. Over 62GB of uncompressed internal intelligence including sensitive customer contracts, aviation safety data, employee PII, and confidential maintenance records.
What we exploited:
- Phished credentials from senior engineer with admin rights to their NAS
- No MFA enforced on SharePoint and its ERP backend
- VPN appliance left unpatched after the vendor released a fix
- Lateral movement to document management system via RDP
- Zero segmentation between their MRO records and customer database
Database Info:
- Platform: Corporate Network / SharePoint + ERP
- Organization: Complete Aircraft Group (CAG)
- Domain: completeaircraftgroup.com
- Country: UK
- Date of Attack: April 2026
- Extraction Completed: April 18-20, 2026
Compromised Data – Complete Aircraft Group Portion
- Customer database: Full names, email addresses, airline/MRO contacts
- Employee PII: National ID cards (UK), passports, medical certificates of mechanics and pilots
- Corporate email archives (.pst files) – CEO, COO, engineering leads
- Aviation maintenance records, logbooks, and engine borescope inspection videos
- Commercial purchase agreements and non-disclosure agreements (NDAs) with global airlines
- Tooling and parts inventory: Airframe-specific for Airbus, Boeing, ATR, Bombardier, De Havilland, Embraer
- Engine health monitoring data including borescope inspection results for on-wing and off-wing scenarios
- Borescope inspection videos and boreblend repair services documentation
- MRO customer list: Part 145 maintenance providers including Aerocare Aviation Services
- Internal financials: Budgets, project costing sheets on engine MRO contracts
- Training manuals for law enforcement inspection programs
- Screen recordings of operational workflows for their engineering team
- ERP access logs and unedited remote desktop session outputs
Sample Data (representative intelligence – redacted):
Additional intelligence:
- The company publicly denied the scope of the breach, but timestamps in internal file metadata show exfiltration started on April 18, 2026 – two days before the public timer.
- Leaked borescope inspection videos directly correlate with earlier aviation sector leaks (Atlas Air 1.2TB dump). Same file naming conventions – cross-correlated.
- Borescope videos reveal specific inspection findings for a Qantas A380 engine (#QF32 lineage) – crack progression measured prior to inflight failure.
- Employee DNI scans expose home addresses of aviation engineers with access to restricted airport areas – prime vector for insider threat recruitment.
- Engine health monitoring data shows clear evidence of maintenance deferrals across two unnamed carriers – potential class action fuel.
- Data was exfiltrated BEFORE any encryption was triggered. Backups are useless.
Why this matters:
- Borescope inspection videos = direct fuel for competitive intelligence (engine wear levels at specific competitors)
- Employee DNI scans = identity theft toolset for anyone targeting restricted zones
- MRO pricing model exposures = all contracting airlines can now renegotiate their heavy maintenance contracts
- Engine health monitoring leaks = liability evidence for engine OEM warranty claims and operational failures
Deliverables:
- Folder structure:
- `/employee_data/passports_nationalIDs/` – scans of UK passports, national ID cards
- `/email_archives/executives/` – .pst files from CEO, COO, head of engineering
- `/maintenance_records/borescope_videos/` – inspection recordings (MP4 format)
- `/maintenance_records/logbooks_engine/` – Excel logs of engine run times
- `/customers/contracts_ndas/` – +50 files covering airline maintenance agreements
- `/internal_financials/budgets/` – Excel sheets of 2025 and 2026 project costs
- `/monitoring_data/screenshots/` – RDP and screen recording outputs from internal engineering workstations
Download:
Today I am releasing the complete data extraction from Complete Aircraft Group (completeaircraftgroup.com) – a UK-based global aviation services, parts, and maintenance provider. Over 62GB of uncompressed internal intelligence including sensitive customer contracts, aviation safety data, employee PII, and confidential maintenance records.
What we exploited:
- Phished credentials from senior engineer with admin rights to their NAS
- No MFA enforced on SharePoint and its ERP backend
- VPN appliance left unpatched after the vendor released a fix
- Lateral movement to document management system via RDP
- Zero segmentation between their MRO records and customer database
Database Info:
- Platform: Corporate Network / SharePoint + ERP
- Organization: Complete Aircraft Group (CAG)
- Domain: completeaircraftgroup.com
- Country: UK
- Date of Attack: April 2026
- Extraction Completed: April 18-20, 2026
Compromised Data – Complete Aircraft Group Portion
- Customer database: Full names, email addresses, airline/MRO contacts
- Employee PII: National ID cards (UK), passports, medical certificates of mechanics and pilots
- Corporate email archives (.pst files) – CEO, COO, engineering leads
- Aviation maintenance records, logbooks, and engine borescope inspection videos
- Commercial purchase agreements and non-disclosure agreements (NDAs) with global airlines
- Tooling and parts inventory: Airframe-specific for Airbus, Boeing, ATR, Bombardier, De Havilland, Embraer
- Engine health monitoring data including borescope inspection results for on-wing and off-wing scenarios
- Borescope inspection videos and boreblend repair services documentation
- MRO customer list: Part 145 maintenance providers including Aerocare Aviation Services
- Internal financials: Budgets, project costing sheets on engine MRO contracts
- Training manuals for law enforcement inspection programs
- Screen recordings of operational workflows for their engineering team
- ERP access logs and unedited remote desktop session outputs
Sample Data (representative intelligence – redacted):
Quote:Quote:
- Employee DNI/ Passport: UK national ID scan – [NAME REDACTED] – Passport number, expiration, issuing authority, home address.
- Email Thread (CEO): "Atlas Air contract renewal – pricing schedules and engine overhaul terms." Outgoing: completeaircraftgroup.com – Receiving: atlasair.com
- Borescope Inspection Video: File: borescope_20250415_QF32.mp4 – Duration: 4:23 – Engine: PW4090 – Findings: "crack observed on 3rd stage HPT blade – needs boroblend"
- MRO Work Order: Customer: [REDACTED AIRLINE] – Engine Serial: [REDACTED] – Man-hours: 672 – Parts ordered: $48,000 – Completion deadline: 2025-09-30
- NDA: Between CAG and [REDACTED AIRCRAFT OEM] – Effective Date: 2025-01-01 – Governing Law: UK – Automatic renewal clause.
- Internal SPY: Converted chat log between engineers discussing "hard landing inspection" for a customer that self-repaired without notifying CAG. Potential safety exposure.
Additional intelligence:
- The company publicly denied the scope of the breach, but timestamps in internal file metadata show exfiltration started on April 18, 2026 – two days before the public timer.
- Leaked borescope inspection videos directly correlate with earlier aviation sector leaks (Atlas Air 1.2TB dump). Same file naming conventions – cross-correlated.
- Borescope videos reveal specific inspection findings for a Qantas A380 engine (#QF32 lineage) – crack progression measured prior to inflight failure.
- Employee DNI scans expose home addresses of aviation engineers with access to restricted airport areas – prime vector for insider threat recruitment.
- Engine health monitoring data shows clear evidence of maintenance deferrals across two unnamed carriers – potential class action fuel.
- Data was exfiltrated BEFORE any encryption was triggered. Backups are useless.
Why this matters:
- Borescope inspection videos = direct fuel for competitive intelligence (engine wear levels at specific competitors)
- Employee DNI scans = identity theft toolset for anyone targeting restricted zones
- MRO pricing model exposures = all contracting airlines can now renegotiate their heavy maintenance contracts
- Engine health monitoring leaks = liability evidence for engine OEM warranty claims and operational failures
Deliverables:
- Folder structure:
- `/employee_data/passports_nationalIDs/` – scans of UK passports, national ID cards
- `/email_archives/executives/` – .pst files from CEO, COO, head of engineering
- `/maintenance_records/borescope_videos/` – inspection recordings (MP4 format)
- `/maintenance_records/logbooks_engine/` – Excel logs of engine run times
- `/customers/contracts_ndas/` – +50 files covering airline maintenance agreements
- `/internal_financials/budgets/` – Excel sheets of 2025 and 2026 project costs
- `/monitoring_data/screenshots/` – RDP and screen recording outputs from internal engineering workstations
Download:
To see this hidden content, you must React with one of the following reactions :
Like,
Love,
Haha,
Wow