aercap.com Listed by slug Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The aercap.com Listed by slug Ransomware Group (reported January 17, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to pressure large enterprises by pairing encryption with data theft and public leak-site listings, turning operational disruption into a reputational and regulatory problem as well. In that landscape, a listing that names a major aviation lessor is noteworthy because of the volume of commercial and contractual information such firms routinely handle.
On 17 January 2023, the ransomware group known as slug listed aercap.com, claiming it had exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail beyond the listing itself is limited. The claim matters because AerCap sits at the centre of global aircraft leasing; any confirmed exposure of internal material could affect airlines, financiers, and counterparties who rely on the integrity of those records.
What happened
According to the available record, aercap.com was listed by the slug ransomware group on 17 January 2023. The group’s claim is that internal files were exfiltrated during a ransomware attack. No public confirmation of the intrusion method, the precise timing of any intrusion, the volume of data taken, or independent verification of the listing has been supplied in the facts at hand. The number of individuals affected is recorded as unknown. Beyond the assertion that internal files were removed, further technical or forensic detail has not been disclosed.
Who is slug?
Slug is identified in the record as a ransomware group. Like other actors in this category, such groups typically gain access to corporate networks, attempt to encrypt systems, and exfiltrate data so they can threaten publication on a dedicated leak site if demands are not met. Listings on those sites are claims by the group; they are not, by themselves, proof that every asserted detail is accurate. No statements attributed to slug specifically about AerCap—beyond the fact of the listing and the claim of internal-file exfiltration—are provided in the available facts. Prior activity and tooling associated with any particular ransomware brand are matters of broader public reporting on the cyber-criminal ecosystem and should not be read as confirmed elements of this incident.
aercap.com and its sector
AerCap describes itself as the world’s largest owner of commercial aircraft and a leader in aviation leasing, supplying airlines with long-term access to passenger and cargo aircraft, engines and helicopters through comprehensive, tailored leasing solutions. The organisation operates in a capital-intensive sector that depends on long-term contracts, asset valuations, maintenance records, financing arrangements and extensive counterparty data. A breach affecting a lessor of this scale is consequential because the same systems that manage fleet deployment and customer relationships often hold commercially sensitive and, in some cases, personal information belonging to employees, customers and business partners across the global aviation supply chain.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or record categories has been disclosed, and the number of people affected is unknown. Organisations in aircraft leasing typically maintain contracts, financial models, technical aircraft records, employee information and correspondence with airlines and lessors; whether any of those categories were among the material taken in this case remains unconfirmed. Exact contents of the claimed exfiltration are therefore not established in the public record.
What's at stake
For individuals whose information may have been present in internal systems, risks include unwanted contact, phishing that leverages accurate organisational detail, and longer-term misuse of personal or employment data if it was included. For AerCap and its counterparties, the stakes centre on possible exposure of commercially sensitive leasing terms, operational schedules or financial arrangements, which could affect negotiations, competitive position and contractual obligations. Regulatory notification duties, contractual breach clauses and the cost of investigation and remediation are ordinary consequences when ransomware claims involve data theft, even when the full scope stays unconfirmed. Because the scale of any personal-data exposure is unknown, the practical impact on any single person cannot yet be quantified from public information alone.
If your data was in this claimed breach
If you have a relationship with AerCap—as an employee, customer contact or commercial counterparty—treat the listing as a prompt to review your exposure rather than as proof that your records were taken. Practical first steps include:
- Monitor account statements and credit reports for unfamiliar activity and consider a fraud alert if you have reason to believe personal identifiers were involved.
- Be alert to phishing or social-engineering attempts that reference aviation leasing, aircraft transactions or AerCap specifically; verify any unexpected request through a known official channel.
- Change passwords on related accounts, enable multi-factor authentication where available, and avoid reusing credentials across services.
- Retain any official notices you receive from the organisation and follow the specific guidance they provide once the scope is clarified.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Public detail on this incident remains limited; further clarity will depend on any additional statements from the organisation or independent verification.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Dublin Airport Listed by everest Ransomware GroupMCARDLESKEATH.COM Listed by clop Ransomware Groupderrytransport.com Listed by clop Ransomware GroupKenya Airways Listed by ransomexx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the aercap.com Listed by slug Ransomware Group →
Publicly posted by slug — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.