MICKAI®ArticlesMRO Aerospace ransomware leak mak…
Article · 5 August 2026

MRO Aerospace ransomware leak makes air-gapped aviation AI the baseline

The 87.3GB leak on 27 July 2026 makes air gapped SIOS the only defensible way to run AI on maintenance data.

Author
Micky Irons
Published
5 August 2026
Follow Micky Irons
LinkedInX
aviationmroransomwareair-gapped aipredictive maintenance
MRO Aerospace ransomware leak makes air-gapped aviation AI the baseline

On 27 July 2026 the CRPxO ransomware group claimed MRO Aerospace and posted 87.3GB of allegedly stolen files on a leak site. Any CAA or EASA regulated maintenance operator still routing work packs and technical records through internet facing cloud AI is a headline in waiting. Air gapped SIOS keeps predictive maintenance inside the hangar firewall.

What CRPxO claimed on 27 July 2026

On 27 July 2026 the CRPxO ransomware group listed MRO Aerospace on its leak site, tagged the target as aerospace and defence, and claimed to have exfiltrated 87.3GB of data. Threat intelligence outfits picked the listing up within hours. Whether every file in the trove is authentic is not yet independently confirmed. The listing itself is the regulatory event, because it puts every peer operator on notice.

For a Continuing Airworthiness Management Organisation, and for any EASA Part 145 or CAA Part 145 approved maintenance organisation, the incident is a live case study in what happens when maintenance workflow touches internet exposed systems.

Why a work pack is not just a document

A modern airline or MRO runs its predictive maintenance and its work pack production through the same tooling. Sensor histories, non destructive test images, tech logs, minimum equipment list decisions and airworthiness directive tracking all flow through the same platform, and increasingly through the same AI models that plan the next check.

When any part of that pipeline calls a US cloud AI vendor, the workflow crosses a boundary the airworthiness authority never signed off. Even where enterprise tiers exclude training on customer prompts, the data still transits a network the operator does not control, and it lands in log stores the operator cannot inspect.

An 87GB leak of that content is not just an embarrassment. It is a forensic map of an operator's tech records for anyone planning a physical attack on an airframe, and it is exactly the material a determined threat actor would want to correlate with rostered aircraft tail numbers.

What CAA and EASA already expect

  • Part 145 approval holders must maintain a Maintenance Organisation Exposition that describes every system in the maintenance workflow
  • The Safety Management System requires a documented cyber security element covering supply chain risk to airworthiness data
  • Continuing airworthiness records under Part M and Part CAMO must be traceable, tamper evident and retrievable for the life of the airframe
  • Any change to a system that processes airworthiness data requires a change management record acceptable to the authority

A cloud AI vendor that changes its model, its data handling terms or its subprocessor list without operator control does not sit inside that expectation. It sits outside it. And in the wake of the MRO Aerospace listing, an inspector who asks the question will not accept a general vendor assurance as the answer.

An air gapped alternative that still works

Predictive maintenance does not need internet scale infrastructure. It needs a fleet of workstations inside the hangar, running vision, time series and language models against the operator's own sensor and record archive. That is the deployment MICKAI was built for.

63 studios sit on one Sovereign Intelligence Operating System, 10 production ready at launch and 53 in development, running on hardware the operator owns, air gapped, with no data egress. Non destructive test image triage, borescope inspection review, tech log summarisation and work pack drafting each run in their own studio inside the same boundary.

Every action the system takes writes to the Open Audit Record, a post-quantum tamper-evident ledger. When the CAA or EASA inspector asks who ran what model against which tech log on which date, the operator answers from the ledger, offline, in a browser.

MRO workflowCloud AI exposureAir gapped SIOS mitigation
Non destructive test image reviewImages sent to a hyperscaler vision endpointVision model runs on hangar hardware, no egress
Work pack draftingPrompts contain tech logs and airworthiness dataLanguage model runs in a studio inside the perimeter
Predictive maintenance forecastingSensor archive uploaded to a US regionTime series model reads from the operator's own store
Regulator evidence requestVendor logs pieced together from a portalLedger replayed offline against signed actions

The procurement question this week

Every Part 145 accountable manager and every CAMO postholder can now be asked the same question in an audit. What internet facing AI service handles our airworthiness data today, and what is the plan to remove it. There is no defensible answer that ends in a general purpose cloud vendor. There are two answers that hold. Stop using AI for that workflow. Or run the AI inside the hangar firewall on hardware the operator owns.

Did CRPxO actually breach MRO Aerospace?

CRPxO listed MRO Aerospace on its leak site on 27 July 2026 and claimed 87.3GB of data. Independent confirmation of the volume and authenticity of every file is still developing. The regulatory relevance does not depend on final confirmation, because the listing itself puts every peer operator on notice.

Why is a work pack more sensitive than it looks?

A work pack contains the maintenance history, tech records and defect log for a specific airframe. In the wrong hands it is an attack surface map of that aircraft. Every operator has a duty of care to keep those records inside a perimeter the airworthiness authority can inspect and the operator can defend.

Can predictive maintenance AI run entirely offline?

Yes. Vision, time series and language models used in modern MRO workflows fit inside on premise hardware and produce useful output against the operator's own archive. The trade off is capital cost, not model quality, and the capital pays back the moment the operator avoids one leak site listing.

What does the Open Audit Record show a CAA inspector?

Every consequential model action, from a borescope image classification to a tech log summarisation, is signed into a post-quantum tamper-evident ledger. The inspector verifies it offline, in a browser, with no network and no trust in the vendor, and the record survives long enough to satisfy Part M retention.

How can a CAA or EASA regulated MRO run predictive maintenance AI without leaking work packs to a ransomware crew?

Run the AI inside the hangar firewall on hardware the operator owns, with no data egress and every action signed into an offline verifiable ledger. Keep the model versions pinned so the inspector can reproduce a given inference against a given tech log. That is the deployment MICKAI is built for.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System built in Britain that runs on hardware the customer owns, on premise and air gapped, with no data egress. Every consequential action is signed into the Open Audit Record, a post-quantum tamper-evident ledger any outside party can verify offline. 63 studios sit on the operating system, 10 production ready at launch and 53 in development, backed by 104 filed UK patent applications across 2,340 claims.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/mro-aerospace-ransomware-air-gapped-maintenance-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles