Iberia, Spain's largest airline and a member of the International Airlines Group (IAG), has disclosed a data breach affecting customer information following a security incident at one of its third-party suppliers. The breach was revealed after a threat actor claimed on hacker forums to possess 77 GB of data allegedly stolen from the airline. Exposed data includes customer names, email addresses, and Iberia Club loyalty card identification numbers. Iberia has confirmed that no account passwords or financial information were compromised in the incident.
Upon discovering the breach, Iberia activated its security protocols, implemented additional technical and organizational measures, and notified relevant authorities. The airline has also enhanced protections around customer email addresses, now requiring verification codes for changes, and is monitoring its systems for suspicious activity. Customers have been advised to remain vigilant for suspicious communications and to report any anomalous activity. The investigation is ongoing in coordination with the affected supplier, and as of the latest update, there is no evidence of fraudulent use of the compromised data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following the disclosure, Iberia said it activated security protocols, strengthened protections, increased monitoring, and notified relevant regulators. The company also stated it had found no evidence of fraudulent use of the exposed data and advised customers to remain vigilant.
Iberia disclosed that a security incident at a third-party supplier exposed customer data including names, email addresses, and Iberia Club loyalty IDs. The airline said passwords and financial information were not affected.
A threat actor claimed to possess 77 GB of data tied to Iberia and offered it for sale for $150,000. The allegedly stolen material reportedly included internal technical documents, maintenance files, engine data, and other sensitive records obtained through a compromised third-party supplier.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.