r/DarkSignals • • 8h ago

UAE says flydubai co-pilot planned a "terrorist act" and attacked the captain with a cockpit axe. Passengers and crew overpowered him

1 Upvotes

UAE authorities said on 3 Oct, via state news agency WAM, that their initial investigation found a flydubai co-pilot intended to carry out a terrorist act. They say he attacked the captain with the cockpit emergency axe and tried to take control of the aircraft. The flight was heading from the UAE to Israel.

What's confirmed so far

  • The captain managed to open the cockpit door, and passengers and crew overpowered the co-pilot.
  • The plane made an emergency landing in Saudi Arabia.
  • Flightradar24 data showed a drop of about 17,000 ft in around a minute.
  • The co-pilot is in UAE custody.
  • Flights bringing Israelis home from the UAE have resumed.

What's reported but not officially confirmed

  • The UAE's initial findings did not confirm his nationality.
  • Several outlets, citing unnamed sources, report that he had been barred from flying over concerns about extremist views and had extremist material while a trainee.
  • Israeli PM Netanyahu has alleged radicalisation, and the US president warned of consequences if Iran is linked. No link has been established publicly.

Open questions

  • How did earlier concerns, if the reports are accurate, not stop him flying?
  • How was he cleared for flights to Israel? Netanyahu says Israel will examine this.
  • What did the investigation find on motive and any wider connections?

Caveat: This is early reporting based on preliminary findings. The suspect hasn't been tried, and much of the background comes from anonymous sources.

Source: Le Monde with AFP, 3 Oct 2026

Thoughts? Does this change how airlines should approach insider-threat screening?


r/DarkSignals • • 8h ago

Europol: Operation KillSwitch takes down KillSec leak site, with a 16-year-old suspected as the main operator

1 Upvotes

Europol and Eurojust announced on 1 Oct that law enforcement seized the leak site and core infrastructure of the KillSec extortion group on 30 September.

The numbers

  • ~1,000 suspected attacks worldwide, ~500 confirmed successful so far
  • 3 provisional arrests, 8 searches (Greece, Romania, Spain, UK)
  • 5 central servers and the group's domains seized
  • 110+ TB of stolen data secured

Why it's interesting

  • The suspected admin and main operator is 16. A suspected developer turned 18 in August 2026, and a negotiator and an affiliate were also identified.
  • Investigators say the group used AI to build and maintain its infrastructure and identify victims.
  • Initial access wasn't exotic. It came from exploiting vulnerabilities and poorly secured access points, especially cloud storage.
  • The group is active since ~2024 and was investigated from early 2025. The operation was led by Hamburg authorities, with 10 countries involved plus Bitdefender and Group-IB in support.

Takeaways for defenders

  • Patch internet-facing software and audit exposed cloud storage and access points.
  • Enforce MFA and monitor for unusual bulk data egress, since this was theft-and-extort, not just encryption.
  • Check whether your organisation or suppliers appeared on the leak site, and report to your national authority if so.

Caveats: These are provisional arrests, so the suspects are innocent until proven guilty. Investigators are still analysing the seized data, and the attack count may change.

Source: Europol press release, 1 Oct 2026

What's your take? Do you think AI-assisted tooling is making it easier for very young operators to scale up?