An update for our airline and airport partners.
Last year, SkyHarbor identified unauthorized activity on a subset of our ground operations systems. We want to be direct about what happened, what we did, and where things stand now.
What happened
Our operations team detected encrypted files across ramp and baggage-handling systems at several client airports. We took the affected systems offline within hours and engaged outside counsel and an independent incident response firm the same day.
What we did
Every affected system was rebuilt from clean images before returning to service. We rotated credentials across staff accounts and vendor integrations, and we brought in a third-party firm to review our environment before we called the incident closed. Ground operations resumed at all client airports within 72 hours.
What partners should know
No passenger data was stored on the affected systems. We have briefed each airport partner directly and continue to work with their security teams on any follow-up questions.
"We slowed everything down on purpose. Every system came back from a clean image, not a patched one, and nothing reopened to partners until an outside firm signed off. That was the only way to be sure."
Questions from airline or airport partners can go through your existing SkyHarbor account contact.
Timeline
-
Ground systems restored at all client airports
Day 3Ramp, baggage, and scheduling systems back to normal operation across every affected site.
-
Third-party review of the environment begins
Day 4Independent incident response firm engaged to validate remediation before systems reopened to partners.
-
Airport partners briefed directly
Day 6Each affected airport's security team received a full technical briefing under NDA.
-
Incident closed
Day 19Third-party review complete, all findings remediated, incident formally closed.