Spain’s national flag carrier, Iberia, has announced that hackers managed to infiltrate a third-party supplier system where customer data is held, becoming the latest airline to join the wave of cyberattacks targeting the aviation industry in recent weeks. The company began notifying affected passengers via email as of Sunday.
Iberia stated that the breach occurred through unauthorised access to an external supplier system where the data is stored, but did not disclose the supplier’s name. However, industry sources noted that many major brands have been subjected to attacks in recent months targeting systems using US-based Salesforce infrastructure.
Worldwide Chain Reaction: Qantas, Air France and KLM Had Also Been Targeted
The first known victim of the cyberattacks thought to be linked to Salesforce was Qantas, which reported a system breach in July. Air France, KLM and other airlines later confirmed they had been targeted by similar attacks.
Iberia’s latest statement once again revealed that the wave of attacks continues on a global scale.
Which Customer Data Was Compromised?
Iberia reported that hackers may have accessed the following information:
- Customer first and last names
- Email addresses
- Frequent flyer (loyalty programme) numbers
The airline stressed that credit card details, passwords or login data were not compromised.
However, experts warn that the stolen data could be used for phishing attacks. Scammers may attempt to deceive customers with fake emails appearing to originate from the airline.
Phishing Risk: Warning to Customers
Phishing emails typically:
- Contain fake links that install malicious software on the victim’s computer.
- Redirect passengers to fraudulent websites resembling the airline’s official page, leading to the theft of personal information.
In its notification email, Iberia urged customers to remain vigilant and stated:
“We immediately activated our security protocols and procedures, implementing all technical and organisational steps to bring the situation under control. We recommend reviewing suspicious communications carefully and contacting our call centre in case of unusual activity.”
77 GB File Claim: No Comment from Iberia Yet
Interestingly, just one week before the announcement of the customer data breach, an online forum claimed that hackers had stolen 77 GB of technical data from Iberia’s internal systems.
According to the allegations, these files include:
- Technical documents for Airbus A320 and A321 aircraft
- AMP maintenance files
- Engine information
- Other internal correspondence and documentation
It was claimed that the data was put up for sale for 150,000 dollars, though this has not yet been verified and Iberia has made no official statement on the matter.
Cyber Risks Within the IAG Group Back in Focus
Headquartered in Madrid, Iberia operates under the IAG (International Airlines Group) umbrella, which also includes major brands such as British Airways, Aer Lingus and Vueling.
IAG has made headlines with serious cyber incidents in the past as well. In 2018, British Airways experienced a breach in which:
- Identity and payment information of 429,612 customers
- Employee usernames and passwords
- Executive Club member login data
were accessed by malicious actors.
Following this incident, the UK Information Commissioner’s Office (ICO) initially planned to fine the airline £180 million, but the penalty was reduced to £20 million due to the impact of the pandemic.
Iberia’s Official Statement: Data “Limited” but the Risk Continues
In its official notification to customers, Iberia reiterated that all security processes had been activated upon detection of the incident, the affected data was limited, and no banking information had been accessed.
The airline stated that customers should remain cautious about suspicious emails, and that the ongoing investigation continues both within the company and at the supplier level.



