On 1 September, the German Air Navigation Services (DFS) fell victim to a cyberattack targeting its internal communications system. Although air traffic was not affected and the consequences appear to be limited for the time being, this attack has highlighted a critical vulnerability. The pro-Russian hacker group APT 28, suspected of being behind the attack, is known for its cyber-espionage activities and is believed to have links to Russian military intelligence (GRU).

This incident highlights the need to implement a strict system of segregation between critical infrastructure and office systems. Such a separation would provide better protection for vital air traffic control functions against malicious intrusions, by restricting access to sensitive systems and minimising the risk of an attack spreading. By strengthening these defences, it would be possible to prevent more serious consequences, such as disruption to air traffic or the exfiltration of sensitive data.
Credits: Le Monde Informatique
