
Iberia Airlines Breach
Nov 25, 2025
21,292,179 rows
Added on Dec 12, 2025
What happened in the Iberia Airlines Breach?
DataBreach.com Team · December 11th 2025, 7:00 pm EST
Overview
In late November 2025, the Everest ransomware group claimed responsibility for a data breach targeting Iberia Airlines, originating from a vulnerability in the Collins Aerospace vMUSE passenger processing system.
On December 9, 2025, following the expiration of their ransom deadline, Everest announced the full publication of the stolen data. The group stated: "Because the company failed to respond by the deadline, we posted all the data."
Leak Details & Dissemination
The threat actors have employed aggressive tactics to ensure the data remains permanently accessible:
- Full Publication: Everest released download links for the complete dataset via file-hosting service Gofile. This includes a specific distribution of "only csv files" (likely containing the structured passenger manifests and loyalty databases).
- Widespread Mirroring: To counter legal takedown efforts, the group explicitly stated that "all the data was duplicated across various hacker forums and leak database sites." They noted that they have re-uploaded files in obscure locations ("places the legal department is unlikely to find") to make total deletion impossible.
- File Evidence: Screenshots provided by the group show a specific archive named
Iberia Air.rarwith a file size of 324.6 GB, confirming a massive exfiltration of data.
Compromised Data (Updated)
With the release of the "CSV only" files, the exposure of structured database information is confirmed.
- Customer PII: Full names, emails, and phone numbers (confirmed).
Claimed -
- Flight Manifests: Passenger lists, seating assignments, and travel dates (linked to vMUSE architecture).
- Loyalty Data: Iberia Plus numbers and associated tier status.
- Internal Data: Technical documents and Collins Aerospace system logs.
Recent News











RansomWho? Inside the Great Ransomware Splintering of 2026
9 days ago

OpenAI Models Escaped a Cyber Test and Breached Major AI Platform Hugging Face
a month ago

Ransomware negotiator stole at least $10M while selling out his own clients
a month ago

Ho-ly G*t: TeamPCP Claims Theft of Thousands of GitHub Internal Repositories
3 months ago

17M Nissan cars impacted by large ransomware attack
4 months ago

Iranian hackers just used Stryker’s own security tools to delete itself
5 months ago

Massive Odido cyberattack leaks customer IBANs and government IDs
5 months ago

Figure breach proves blockchain cannot save us from human error
6 months ago

Substack notifies users of data breach affecting nearly 700,000 accounts
6 months ago

UPenn claims "Under 10" victims in 1.2M breach involving donors like Trump and Musk
6 months ago

How 0apt is Using Random Noise to Fake a Ransomware Empire
6 months ago