Lyce · Hybrid Watch

hw_c3ed4f0697dfbc22

Pro-Russian “Killnet” hackers knock more than a dozen U.S. airport websites offline via DDoS attacks.

Public websites for more than a dozen major U.S. airports were temporarily taken offline by distributed-denial-of-service (DDoS) attacks, with the Russian-speaking hacktivist collective Killnet claiming responsibility. The attacks targeted public-information portals, including LaGuardia and Chicago O’Hare, making it difficult for travellers to access data on wait times and capacity, even though core airport operations such as air-traffic control and internal communications were reportedly unaffected. U.S. officials described the incident as a “denial of public access” event rather than a safety-critical systems breach, yet it demonstrated Killnet’s ability to coordinate simultaneous strikes on multiple transport targets. Cybersecurity analysts and U.S. agencies have characterised Killnet as a pro-Kremlin group whose operations align with Russian interests, blurring the boundary between state and non-state actors in Moscow’s wider hybrid toolbox. The October campaign followed Killnet’s earlier calls on Telegram for attacks against Western critical infrastructure in states supporting Ukraine, and it coincided with similar DDoS incidents against German rail communications. While the technical impact on U.S. airports was limited and short-lived, the highly visible nature of the target ensured media coverage and public awareness disproportionate to the immediate damage.

Occurrence
2022-10-10
Publication
2022-10-09T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
US
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-10-09T22:00:00Z

    Public websites for more than a dozen major U.S. airports were temporarily taken offline by distributed-denial-of-service (DDoS) attacks, with the Russian-speaking hacktivist collective Killnet claiming responsibility. The attacks targeted public-information portals, including LaGuardia and Chicago O’Hare, making it difficult for travellers to access data on wait times and capacity, even though core airport operations such as air-traffic control and internal communications were reportedly unaffected. U.S. officials described the incident as a “denial of public access” event rather than a safety-critical systems breach, yet it demonstrated Killnet’s ability to coordinate simultaneous strikes on multiple transport targets. Cybersecurity analysts and U.S. agencies have characterised Killnet as a pro-Kremlin group whose operations align with Russian interests, blurring the boundary between state and non-state actors in Moscow’s wider hybrid toolbox. The October campaign followed Killnet’s earlier calls on Telegram for attacks against Western critical infrastructure in states supporting Ukraine, and it coincided with similar DDoS incidents against German rail communications. While the technical impact on U.S. airports was limited and short-lived, the highly visible nature of the target ensured media coverage and public awareness disproportionate to the immediate damage.