Dublin Airport Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Dublin Airport was listed by the everest ransomware group on October 26, 2025, after internal files were exfiltrated in a ransomware attack. Anyone connected to the airport should check official updates and monitor their accounts for signs of compromise.
Ransomware groups continue to target critical infrastructure and high-visibility organisations across Europe, using data theft and public leak-site pressure as leverage. In this environment, a listing of a major airport on a ransomware group's site draws attention because of the operational sensitivity of aviation and the volume of personal and commercial data such facilities routinely handle. On 26 October 2025, Dublin Airport appeared on the leak site of the Everest ransomware group, which claimed responsibility for a ransomware attack involving the exfiltration of internal files. Public detail remains limited; the number of people affected is unknown, and independent confirmation of the full scope has not been released.
The listing itself is a claim by the group rather than a verified disclosure by the airport operator. For passengers, staff, partners and nearby communities, the episode underscores how quickly operational systems can become the focus of cyber extortion campaigns and why monitoring such claims matters even when full technical details are still emerging.
Breaking down the breach
According to the available record, Dublin Airport was listed by the Everest ransomware group on 26 October 2025. The group asserts that internal files were exfiltrated during a ransomware attack. No public figure has been given for the volume of data taken, the precise systems affected, or the number of individuals whose information may be involved. The method of initial access, the duration of any intrusion, and whether encryption was also deployed remain undisclosed in the material provided. Because the listing originates from the threat actor's own site, it should be treated as an unverified claim until the operator or independent investigators publish corroborating findings. At present the only confirmed elements are the date of the listing, the named organisation, and the group's statement that internal files were removed as part of the attack.
Who is everest?
Everest is a ransomware operation that has been active for several years and is known for double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to publish it if a ransom is not paid. The group maintains a public leak site on which it posts the names of organisations it claims to have compromised, often accompanied by samples or full archives of stolen material. Everest has previously targeted a range of sectors including manufacturing, professional services and public-facing entities, typically seeking payment in cryptocurrency. Its public communications emphasise the volume and sensitivity of data taken rather than technical sophistication alone. In the present case the group claims Dublin Airport as a victim and states that internal files were exfiltrated; no further specific assertions about this incident appear in the available facts, and those claims have not been independently verified here.
Who is Dublin Airport?
Dublin Airport, located in Collinstown, Fingal, Ireland, is the principal international airport serving the capital city and is operated by the Dublin Airport Authority (DAA). It ranks among Europe's busier airports, handling flights to more than 180 destinations operated by over 40 airlines and featuring two terminals together with extensive retail, dining and ground-transport facilities. As a major transport hub it processes large volumes of passenger, crew, cargo and commercial data every day, including booking records, security screening information, staff credentials, supplier contracts and operational logistics. A cyber incident at such a facility is consequential because disruption or data exposure can affect flight schedules, passenger trust, regulatory compliance under European data-protection rules, and the wider supply chain of airlines, ground handlers and retailers that rely on the airport's systems. Even when core flight operations continue, the reputational and legal implications of a claimed data theft remain significant for any organisation of this scale and public profile.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of data types—such as passenger manifests, employee records, financial documents or security protocols—has been publicly confirmed. Organisations of this kind typically hold a mixture of personal data (names, contact details, travel documents, employment information), commercial contracts, operational schedules and internal communications. Because the precise contents remain unconfirmed, it is not possible to state with certainty which categories were taken or whether any personal data of passengers or staff is among the material. The Everest listing asserts only that internal files were removed; readers should treat any more detailed descriptions circulating online as unverified until official statements or forensic reports appear.
What's at stake
For individuals whose data may have been involved, the practical risks include potential misuse of personal details for phishing, identity fraud or social-engineering attempts that reference travel or employment. Staff could face targeted approaches that exploit knowledge of internal processes. For the airport operator the stakes include regulatory scrutiny under data-protection law, possible contractual liabilities toward airlines and partners, and the operational cost of investigating and remediating any compromise. Even if core aviation systems were unaffected, the mere public claim of a breach can erode confidence among travellers and commercial tenants. Because the number of people affected is unknown and the exact data types are unconfirmed, the full extent of these risks cannot yet be quantified; the prudent course is to assume that any internal material could contain sensitive elements until proven otherwise.
What to do if you're exposed
If you have reason to believe your information may have been among the files claimed by Everest, begin by monitoring financial accounts and credit reports for unusual activity and treat unsolicited emails or calls that reference Dublin Airport or recent travel with heightened caution. Change passwords on any accounts that reuse credentials linked to airport-related services, and enable multi-factor authentication wherever it is available. Consider placing a fraud alert with relevant credit agencies if you hold Irish or European financial products. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; such a scan provides an early indication of whether your details are circulating more widely and can guide further protective steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Iberia Airlines Listed by everest Ransomware GroupIberia Listed by everest Ransomware GroupAir Miles España, S.A Listed by everest Ransomware GroupAir Arabia Listed by everest Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Dublin Airport Listed by everest Ransomware Group →
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.