Ukraine and its neighbours, explained

Advertisement

Home › World › What did Europe do after the Ryanair diversion?

World

What did Europe do after the Ryanair diversion?

Summary

A look back at the measures and demands that followed the diversion of Ryanair Flight 4978 by Belarus, and at a ransomware disclosure from the same days.

How far was Europe ready to go in response to Belarus's diversion of a Ryanair flight? By 27 May 2021, the answers were already taking shape.

Three days earlier, on 24 May 2021, the European Union banned all Belarusian airlines from using its airports and airspace. The bloc described the diversion of Ryanair Flight 4978 as a hijacking. It also placed sanctions on the officials believed to be involved in the operation.

The day before, on 23 May 2021, NATO had demanded an international investigation into Belarus's diversion of the flight. The two responses ran side by side: the EU imposed penalties, while the alliance called for an independent inquiry.

A separate disclosure

On 21 May 2021, another story surfaced that concerned the region's security picture only at a distance. CNA Financial, the seventh-largest commercial insurer in the United States, revealed that it had been hit by a ransomware attack in March 2021. The company said it paid $40 million to a group named Phoenix two weeks after a trove of its data was stolen and its officials were locked out of their network.

The attackers used malware called Phoenix Locker, a variant of ransomware dubbed Hades. Cybersecurity experts said Hades was created by a Russian cybercrime syndicate known as Evil Corp. In December 2019, the US Treasury Department had announced sanctions on 17 individuals and six entities linked to Evil Corp. That designation made it illegal for a US company to knowingly pay a ransom to the group.

Taken together, the reports from those days show governments reaching for sanctions, bans and calls for investigation, while a major payment to a hacking group raised questions of its own.

Related analysis