Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026

Badges, Bytes and Blackmail

February 7, 2026

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»WestJet Data Breach Impacts 1.2 Million Customers
News

WestJet Data Breach Impacts 1.2 Million Customers

Team-CWDBy Team-CWDOctober 3, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Canadian airline WestJet has revealed that 1.2 million customers have been impacted by a data breach following a June 2025 cyber-attack.

The firm provided the update in a data breach notification to the Office of the Maine Attorney General on September 29.

Following an investigation into the network intrusion, WestJet found that a range of customers’ personal information was accessed by the “criminal third party.”

This included names, contact details, documents and information provided in connection with their reservation and travel, and data regarding their relationship with WestJet.

Additionally, for WestJet Rewards Members, information linked to their membership may have been accessed by the attackers. This data could include their WestJet Rewards ID number and points balance on the date of the incident, as well as other information linked to the use of their account.

Passwords used to access Rewards accounts were not included in the breach.

WestJet RBC Mastercard, WestJet RBC World Elite Mastercard, or WestJet RBC World Elite Mastercard for Business cardholders may have had additional information compromised. This may include a credit card identifier type and information about changes to their WestJet points balance.

The data involved varies for individual customers, who are each being contacted by the firm about the incident.

“Importantly, credit card or debit card numbers, expiry dates and CVV numbers, and guest user passwords, were not compromised, and our systems are fully secure. At no time was the safety and integrity of our operations ever in question,” WestJet wrote in its notification letter to customers.

The airline acknowledged that the stolen data could be used for identity theft and fraud attacks, including in the context of any booked travel.

While it is not aware of any such misuse, the firm is offering identity theft protection services to relevant individuals “where appropriate.”

WestJet is cooperating with Canadian law enforcement and government agencies as it continues to investigate the incident.

No details about how the attack occurred have been shared. WestJet said the attack was carried out by a “sophisticated, criminal third party,” who gained unauthorized access to its systems.

“Given the significant importance of data security to the integrity of our business, we are prepared for incidents of this nature and followed our response planning by taking immediate action to contain the incident and secure our systems. As a result, at no point was the safety and integrity of our airline operations in question,” WestJet noted.

Air Travel Under Heavy Attack

The WestJet data breach, first identified on June 13, came amid a plethora of cyber incidents impacting major airlines in the summer months.

Other victims included Australian airline Qantas and Hawaiian Airlines.

Qantas later revealed that nearly six million customers had their personal data breached.

The main aim of these attacks appears to have been data theft rather than targeting the airlines’ physical operations.

The FBI warned on 27 June that the notorious Scattered Spider actor was actively targeting airlines with ransomware and data extortion attacks. The group targets third-party IT providers with social engineering techniques for initial access.

In September, a cyber-attack targeting a third-party software supplier caused flight cancellations and delays at several European airports, including London’s Heathrow Airport and terminals in Brussels, Berlin and Dublin.

UK authorities revealed on September 24 that they had arrested a man in connection with the attack.

Image credit: Ramon Cliff / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleUNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors
Next Article Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software
Team-CWD
  • Website

Related Posts

News

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026
News

Badges, Bytes and Blackmail

February 7, 2026
News

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Common Apple Pay scams, and how to stay safe

January 22, 2026

AI-powered financial scams swamp social media

September 11, 2025

What’s at stake if your employees post too much online

December 1, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.