Air Arabia DataBase on sale for $2 Million Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Air Arabia's internal files were listed for sale by the Everest ransomware group on October 25, 2025. If you have flown with Air Arabia or shared personal details with the airline, review your accounts for unusual activity and change passwords where necessary.
Ransomware groups continue to target airlines and travel operators, treating passenger systems and internal databases as high-value assets that can be exfiltrated and offered for sale. In this environment, claims of stolen corporate data surface regularly on leak sites, often before independent verification is possible.
On 25 October 2025, the Everest ransomware group listed Air Arabia, stating that a database of internal files obtained in a ransomware attack was available for purchase at two million dollars. The number of people affected remains unknown, and public detail on the precise contents is limited. The listing itself constitutes a claim by the group rather than confirmed independent evidence.
Inside the incident
According to the available record, the Everest ransomware group publicly listed Air Arabia on its leak site on 25 October 2025. The headline associated with the listing described an Air Arabia database offered for sale at two million dollars and attributed the material to internal files exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the duration of any intrusion, the volume of data taken, or confirmation that the sale occurred—have been disclosed in the public facts. The number of individuals whose information may have been involved is recorded as unknown. Beyond the group’s own claim that internal files were removed, the incident’s scale and exact timeline remain unconfirmed.
Inside everest
Everest is a ransomware operation that has appeared in public reporting as a double-extortion actor: it encrypts systems while also copying data and threatening to publish or sell it if a ransom is not paid. Like other groups of this type, it maintains a leak site where it posts victim names, sample files, and sale prices to apply pressure. Public knowledge of Everest indicates it has listed organisations across multiple sectors, often claiming to hold internal documents, databases, or employee and customer records. In the present case the group claims to have obtained Air Arabia internal files and to be offering a database for two million dollars; those assertions rest solely on the listing and have not been independently verified in the available facts. No additional statements attributed specifically to Everest about this victim appear in the record.
Who is Air Arabia?
Air Arabia is a low-cost airline headquartered in the United Arab Emirates. It operates scheduled passenger services across the Middle East, North Africa, Central Asia and parts of Europe, serving both leisure and business travellers. As a commercial carrier it maintains reservation systems, passenger name records, loyalty programmes, employee records and operational databases. Organisations of this kind routinely hold names, contact details, travel itineraries, passport or identity information, payment-related data and internal corporate files. A breach claim involving such an airline therefore raises concerns about both customer privacy and the integrity of operational systems, even when the precise data set remains unconfirmed.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No specific categories—such as passenger lists, payment card numbers, employee credentials or technical schematics—are named. Because the exact contents are undisclosed, it is not possible to state with certainty what personal or corporate information was involved. Airlines typically store booking data, identity documents, contact information and internal correspondence; any of these could theoretically have been among the files claimed by the group. Until independent confirmation is available, the nature and sensitivity of the material remain unconfirmed.
The real-world impact
For individuals, the principal risk is that personal details held by an airline could later appear in criminal markets or be used for phishing, identity fraud or social-engineering attempts. Without a confirmed list of affected people or data types, the scale of that risk cannot be quantified. For the organisation, a public ransomware listing can damage customer trust, invite regulatory scrutiny under data-protection regimes, and create operational distraction while systems are examined and restored. Because the number of people affected is unknown and the sale price is merely the group’s stated asking figure, the concrete financial or reputational consequences remain speculative at this stage. The incident nonetheless illustrates how ransomware claims alone can generate lasting uncertainty for both customers and the company.
If your data was in this claimed breach
Anyone who has flown with or otherwise shared information with Air Arabia should treat the listing as a prompt for caution rather than confirmed exposure. Practical first steps include monitoring bank and credit statements for unexpected activity, enabling multi-factor authentication on email and travel accounts, and being alert to phishing messages that reference recent bookings or airline communications. Changing passwords on any accounts that reuse credentials associated with airline logins is also advisable. Readers can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets; such a check provides an additional, independent signal while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Atlas Air Listed by everest Ransomware GroupChrysler Listed by everest Ransomware GroupSarmap Listed by everest Ransomware GroupIberia Airlines Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.