LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › egyptair.com 5 sell Listed by funksec Ransomware Group

HIGH severityUnverified claimHow we verify

egyptair.com 5 sell Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 24, 2024
egyptair.com 5 sell Listed by funksec Ransomware Group

Reported December 24, 2024.

HIGH
Severity
December 24, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

egyptair.com 5 sell was listed by the funksec ransomware group on December 24, 2024, with internal files reportedly exfiltrated. An undisclosed number of people may be affected; check egyptair.com and change any exposed credentials immediately.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target organisations across aviation, travel and related sectors, using data theft and public leak-site listings as leverage. Against that backdrop, a listing dated 24 December 2024 attributed to the funksec ransomware group named egyptair.com 5 sell as a victim. Public detail remains limited: the number of people affected is unknown, and the only data category described is internal files said to have been exfiltrated. The listing itself is an unverified claim by the group; no independent confirmation of the incident’s scope or success has been provided in the available record.

For passengers, employees and partners of an airline-linked entity, any such claim raises practical questions about what may have been taken and what steps are sensible while fuller information is absent. The following sections set out only what the record states and the established public context around the actor and the sector.

Breaking down the breach

According to the available facts, egyptair.com 5 sell was listed by the funksec ransomware group on 24 December 2024. The report characterises the event as a ransomware attack in which internal files were allegedly exfiltrated. No figure is given for the volume of data, the number of systems involved, or the number of individuals whose information may have been included. Timing of the initial intrusion, the method of entry, and whether encryption was also deployed are undisclosed. The listing on the group’s leak site constitutes a claim by funksec; it has not been independently verified in the material provided. People affected are recorded simply as unknown.

Who is funksec?

Funksec is a ransomware operation that became publicly visible in late 2024. Like many contemporary groups, it has been observed using double-extortion tactics: encrypting systems where possible while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Public reporting has noted the group’s relatively rapid appearance and its use of automated or AI-assisted tooling in some operational steps, though the precise technical stack varies by incident. Funksec typically posts victim names and, in some cases, sample files to pressure organisations. Prior listings have spanned multiple sectors and geographies; the group’s claims are routinely treated by researchers as unverified until corroborated by the victim or by forensic evidence. Nothing in the present record supplies additional statements by funksec about egyptair.com 5 sell beyond the fact of the listing itself.

Who is egyptair.com 5 sell?

The organisation named in the listing is egyptair.com 5 sell. Public background material associated with the report identifies EgyptAir as Egypt’s flag-carrier airline, headquartered in Cairo and operating scheduled passenger and freight services across the Middle East, Europe, Africa, Asia and the Americas. As a Star Alliance member it maintains extensive codeshare and frequent-flyer arrangements. Airlines of this type routinely manage large volumes of passenger reservation data, crew and employee records, operational schedules, maintenance logs, and commercial contracts. A breach affecting systems linked to such an organisation is consequential because aviation data often includes personal identifiers, travel itineraries, payment-related information and internal operational detail that can be reused for fraud, social engineering or competitive intelligence. The precise corporate relationship between the listed domain string “egyptair.com 5 sell” and the airline’s core operations is not further clarified in the facts; the listing simply presents that name as the victim.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown—such as passenger manifests, employee directories, financial records, source code or authentication credentials—is supplied. Because the exact contents remain unconfirmed, it is not possible to assert which specific categories of personal or corporate data were involved. Organisations in the airline sector typically hold passenger contact details, passport or identity numbers, booking histories, payment tokens, crew rosters and internal correspondence. Whether any of those categories were present among the exfiltrated files is unknown. The record likewise does not indicate whether the data were later published, sold or merely threatened.

The real-world impact

When internal files leave an organisation’s control, the immediate risks are identity fraud, targeted phishing and unauthorised account access for anyone whose details appear in those files. Passengers or staff whose names, contact information or travel records were included could face attempts to reset passwords, open fraudulent accounts or craft convincing social-engineering messages. For the organisation itself, the consequences may include operational disruption, regulatory notification duties, reputational harm and the cost of forensic investigation and system restoration. Because the number of affected individuals is unknown and the precise data types are undisclosed, the scale of these risks cannot be quantified from the public record. The listing alone does not establish that every customer or employee may have been exposed; it establishes only that funksec claims to have taken internal files.

What to do if you're exposed

Anyone who has used services associated with EgyptAir or related entities should treat the claim as a prompt for ordinary hygiene rather than panic. Change passwords on accounts that reuse credentials, enable multi-factor authentication wherever available, and monitor bank and credit statements for unexpected activity. Be alert to phishing messages that reference recent travel or personal details. If you believe your information may have been involved, consider placing fraud alerts with credit bureaux where that option exists in your jurisdiction. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides an additional data point but does not confirm or rule out involvement in this specific incident. Official statements from the organisation, if and when they appear, remain the most reliable source for further guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyegyptair.com 5 sell security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See egyptair.com 5 sell’s full breach history →

More recent breaches

egyptair.com 5 with 10K ! Listed by funksec Ransomware GroupDecember 23, 2024tsag-agaar.gov.mn Listed by funksec Ransomware GroupDecember 31, 2024carsbeat.com Listed by funksec Ransomware GroupDecember 21, 2024kurosu.com.py Listed by funksec Ransomware GroupDecember 10, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the egyptair.com 5 sell Listed by funksec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by funksec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram