Discovered
2026-10-09 19:26 UTC
Est. attack date
2026-10-06
Sector
Agriculture and Food Production
Education
Energy & Utilities
Financial Services
Government & Defense
Healthcare
Hospitality
Manufacturing
Other
Professional Services
Retail & E-Commerce
Technology
Transportation
Description:
skyplan.com zoominfo.com/c/skyplan-services-ltd/81691062 Skyplan Services Limited is a private, self-funded aviation flight planning and dispatch company founded in 1983 in Calgary, Alberta, Canada, with major operations in Dubai (UAE), China, and Finland, employing ~85 people. It generates estimated annual revenue of ~$7M with zero external investment over its 43-year history. Its flagship Aurora Flight Planning System (SaaS, web-based since 1998 — a global pioneer) covers 24,000+ airports, 450+ aircraft types, and 1,600+ fuel locations worldwide. Services include contract flight planning, international trip support, aviation fuel sales, permits/slots, ground handling, and 24/7 dispatch — saving airlines up to 5% in fuel costs through route optimization. The company is ranked #1 among independent flight planning competitors (Tracxn), led by CEO Mohammad Sami, competing against giants like Jeppesen (Boeing), ARINCDirect (Collins Aerospace), and Lido (Lufthansa Systems).
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 12
Third Party Employee Credentials: 1
External Attack Surface:
8
Exposure Report
by ParanoidLab
221
Passwords
11 critical
DNS Records:
The following DNS records were found for the victim's domain.
-
d127877a.ess.barracudanetworks.com.
Barracuda
-
d127877b.ess.barracudanetworks.com.
Barracuda
-
skyplan-com.mail.protection.outlook.com.
Microsoft 365
- gqv3c4shpn64oldnmb35g4njq2
- ot9cv9q2c9c4r1j07e3o1iu2s4
- h1g3d22jbdjmlol88ekcgel2fu
- cfgg9oikc9d4fj785tua9ku6g7
- v=spf1 include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com -all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.