LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Air Arabia DataBase on sale for $2 Million Listed by everest Ransomware Group

HIGH severityUnverified claimHow we verify

Air Arabia DataBase on sale for $2 Million Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 25, 2025
Air Arabia DataBase on sale for $2 Million Listed by everest Ransomware Group

Reported October 25, 2025.

HIGH
Severity
October 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Air Arabia's internal files were listed for sale by the Everest ransomware group on October 25, 2025. If you have flown with Air Arabia or shared personal details with the airline, review your accounts for unusual activity and change passwords where necessary.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target airlines and travel operators, treating passenger systems and internal databases as high-value assets that can be exfiltrated and offered for sale. In this environment, claims of stolen corporate data surface regularly on leak sites, often before independent verification is possible.

On 25 October 2025, the Everest ransomware group listed Air Arabia, stating that a database of internal files obtained in a ransomware attack was available for purchase at two million dollars. The number of people affected remains unknown, and public detail on the precise contents is limited. The listing itself constitutes a claim by the group rather than confirmed independent evidence.

Inside the incident

According to the available record, the Everest ransomware group publicly listed Air Arabia on its leak site on 25 October 2025. The headline associated with the listing described an Air Arabia database offered for sale at two million dollars and attributed the material to internal files exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the duration of any intrusion, the volume of data taken, or confirmation that the sale occurred—have been disclosed in the public facts. The number of individuals whose information may have been involved is recorded as unknown. Beyond the group’s own claim that internal files were removed, the incident’s scale and exact timeline remain unconfirmed.

Inside everest

Everest is a ransomware operation that has appeared in public reporting as a double-extortion actor: it encrypts systems while also copying data and threatening to publish or sell it if a ransom is not paid. Like other groups of this type, it maintains a leak site where it posts victim names, sample files, and sale prices to apply pressure. Public knowledge of Everest indicates it has listed organisations across multiple sectors, often claiming to hold internal documents, databases, or employee and customer records. In the present case the group claims to have obtained Air Arabia internal files and to be offering a database for two million dollars; those assertions rest solely on the listing and have not been independently verified in the available facts. No additional statements attributed specifically to Everest about this victim appear in the record.

Who is Air Arabia?

Air Arabia is a low-cost airline headquartered in the United Arab Emirates. It operates scheduled passenger services across the Middle East, North Africa, Central Asia and parts of Europe, serving both leisure and business travellers. As a commercial carrier it maintains reservation systems, passenger name records, loyalty programmes, employee records and operational databases. Organisations of this kind routinely hold names, contact details, travel itineraries, passport or identity information, payment-related data and internal corporate files. A breach claim involving such an airline therefore raises concerns about both customer privacy and the integrity of operational systems, even when the precise data set remains unconfirmed.

What data was at risk

The facts state only that internal files were exfiltrated in a ransomware attack. No specific categories—such as passenger lists, payment card numbers, employee credentials or technical schematics—are named. Because the exact contents are undisclosed, it is not possible to state with certainty what personal or corporate information was involved. Airlines typically store booking data, identity documents, contact information and internal correspondence; any of these could theoretically have been among the files claimed by the group. Until independent confirmation is available, the nature and sensitivity of the material remain unconfirmed.

The real-world impact

For individuals, the principal risk is that personal details held by an airline could later appear in criminal markets or be used for phishing, identity fraud or social-engineering attempts. Without a confirmed list of affected people or data types, the scale of that risk cannot be quantified. For the organisation, a public ransomware listing can damage customer trust, invite regulatory scrutiny under data-protection regimes, and create operational distraction while systems are examined and restored. Because the number of people affected is unknown and the sale price is merely the group’s stated asking figure, the concrete financial or reputational consequences remain speculative at this stage. The incident nonetheless illustrates how ransomware claims alone can generate lasting uncertainty for both customers and the company.

If your data was in this claimed breach

Anyone who has flown with or otherwise shared information with Air Arabia should treat the listing as a prompt for caution rather than confirmed exposure. Practical first steps include monitoring bank and credit statements for unexpected activity, enabling multi-factor authentication on email and travel accounts, and being alert to phishing messages that reference recent bookings or airline communications. Changing passwords on any accounts that reuse credentials associated with airline logins is also advisable. Readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets; such a check provides an additional, independent signal while official details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAir Arabia security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Air Arabia’s full breach history →
RelatedMore incidents at Air Arabia

More recent breaches

Atlas Air Listed by everest Ransomware GroupFebruary 6, 2026Chrysler Listed by everest Ransomware GroupDecember 25, 2025Sarmap Listed by everest Ransomware GroupDecember 2, 2025Iberia Airlines Listed by everest Ransomware GroupNovember 25, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Air Arabia DataBase on sale for $2 Million Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram