Security
Iberia Exposes Customer Data in Vendor Security Breach
Recently, Spanish airline giant Iberia disclosed a data security breach that originated from a breach at one of its suppliers.
This revelation comes in the wake of a cyber threat actor’s claim on hacker forums that they have obtained 77 GB of data allegedly taken from the airline.
Details of the Data Breach
Iberia, a prominent airline in Spain and a part of the International Airlines Group (IAG), stated that unauthorized access to a supplier’s systems led to the exposure of specific customer information.
According to an email reviewed by threat intelligence platform Hackmanac, the compromised data potentially includes:
- Customer’s name and surname
- Email address
- Loyalty card (Iberia Club) identification number
The airline clarified that customers’ Iberia account login credentials and passwords were not compromised, and no banking or payment card details were accessed.

Iberia’s security notice emphasized their immediate response to the incident, activating security protocols and implementing measures to contain and prevent further breaches.
In response to the breach, Iberia has enhanced security measures for customer email addresses, requiring a verification code for any account modifications.
The airline is actively monitoring its systems for suspicious activities, with authorities notified and investigations ongoing in collaboration with the affected supplier.
The email also urged vigilance against potential fraudulent activities and advised customers to report any suspicious behavior to their call center.
Connection to Previous Data Theft Claims
The disclosure of the breach follows a recent claim by a threat actor who alleged access to 77 GB of data from Iberia, seeking to sell it for a significant sum.
In the online forum post, the threat actor asserted that the data, extracted from the airline’s internal servers, contained technical information and internal documents.

While it remains unclear if the leaked data is related to Iberia’s recent incident, the airline attributes the breach to a third-party vendor rather than internal servers.
BleepingComputer has not independently verified the authenticity of the advertised data. Further inquiries have been made to Iberia’s press team for clarification.
Meanwhile, Iberia advises customers and partners to remain cautious of any suspicious messages purportedly from the airline, as they could be phishing attempts.
With MCP (Model Context Protocol) emerging as the standard for connecting LLMs to tools and data, security teams are prioritizing measures to ensure the safety of these new services.
Discover 7 best practices in this free cheat sheet that you can implement immediately.
-
Facebook4 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook4 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook4 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook4 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook2 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook2 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook2 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple4 months agoMeta discontinues Messenger apps for Windows and macOS

