The Everest ransomware gang is claiming to have exfiltrated Boeing proprietary source code from a breach of UAE carrier FlyDubai - a claim that, if verified, raises intellectual property and technology liability questions well beyond a standard data breach.
Everest has listed FlyDubai on its dark web leak site with a six-day negotiation timer, according to Cybernews, which first reported the listing. No data samples have been publicly released to verify the claims, and FlyDubai had not responded publicly at time of writing.
The alleged dataset totals 4.36GB and includes personal records for 2,862 employees, pilot training materials, operational directives on safety-critical procedures, and what Everest claims are 2,827 Java source code files for Boeing's Performance Engineers Tool - software used to calculate takeoff weights, landing distances, fuel planning, and engine-out scenarios. More than 2,000 of those files are allegedly marked "Boeing Proprietary, Confidential, and/or Trade Secret." A 190-page CFM engine manual and an Airbus ETOPS guide, both marked confidential, are also claimed.
Cybernews researchers warn the alleged data could support phishing and social engineering attacks against airline staff, and poses competitive intelligence and legal risks for the carrier.
A standard ransomware breach against an airline triggers familiar coverage questions: cyber business interruption, notification costs, crisis management. The Boeing source code claim introduces a different category of exposure entirely.
If proprietary software code belonging to Boeing was exfiltrated via a downstream operator's systems, the IP liability chain runs in multiple directions. Boeing may have claims against FlyDubai for failure to protect its confidential material under licensing or supply agreements. Third parties who rely on the integrity of Performance Engineers Tool calculations - including other airlines, maintenance organizations, and regulators - could face claims if the code is tampered with or if knowledge of its vulnerabilities is exploited. And FlyDubai itself faces potential technology E&O exposure if its handling of Boeing's proprietary systems falls below the contractual or regulatory standard of care.
For technology E&O and professional liability underwriters with aviation or aerospace clients, the question is whether those policies contemplate third-party IP exfiltration as a covered trigger - or whether it falls into a gap between the cyber policy and the E&O policy that neither was written to address.
Everest is not a peripheral actor. The Russia-linked group is behind the Collins Aerospace attack that disrupted European airports, a breach of Coca-Cola's Middle East distributor, and 2026 attacks on Frost Bank and Citizens Bank in the US, according to Cybernews. Its operation as an initial access broker - selling network footholds when direct extortion fails - means a confirmed FlyDubai breach could generate downstream incidents at connected partners or vendors.
The broader pattern matters for brokers whose clients are not airlines. As IBA reported, US authorities boarded two crude oil tankers in August 2026 following cyber incidents in which engine-room systems were allegedly manipulated.
Harriet Gruen, head of cyber threat intelligence at Howden Re, told IBA that "as ships become more connected, and reporting requirements improve, we should expect greater visibility of cyber activity affecting maritime operations." The same dynamic applies across any sector where operational technology is increasingly networked - logistics, manufacturing, energy, critical infrastructure. The transport sector is where that exposure is most visible right now, but it is not where it stops.
For brokers with clients in those sectors, the FlyDubai incident is the prompt to check three things before the next renewal: whether cyber policies cover exfiltration of third-party proprietary data as distinct from personal data; whether business interruption extends through a ransomware negotiation period; and whether tech E&O contemplates IP liability from a cyber event. The six-day timer Everest has set may or may not produce a resolution. Either way, the data the gang claims to hold does not become less sensitive if FlyDubai pays. It simply changes who holds it.