FAI Aviation Group (fai.ag) - The biggest leak ever Listed by J Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
FAI Aviation Group (fai.ag) was listed by the J Ransomware Group on September 23, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; check your accounts and monitor for suspicious activity.
Ransomware groups continue to target organisations that hold operationally sensitive data, including those in aviation and specialised transport. Listings on criminal leak sites remain a common pressure tactic, even when independent confirmation of the claimed scale or contents is limited. Against that backdrop, FAI Aviation Group appeared on a J Ransomware Group listing dated 23 September 2025.
Public reporting indicates the group claimed to have exfiltrated internal files from the German-based aviation services provider and described the incident as “the biggest leak ever.” The number of people affected is unknown, and further technical details have not been disclosed. The listing itself is an unverified claim by the threat actor.
What happened
On 23 September 2025, FAI Aviation Group (fai.ag) was listed by the J Ransomware Group. The listing asserted that internal files had been exfiltrated in a ransomware attack and characterised the event as “the biggest leak ever.” No independent confirmation of the volume, exact timing of the intrusion, or encryption status of systems has been made public. The number of individuals whose data may have been involved remains unknown. Beyond the group’s claim of data theft, the method of initial access and any subsequent operational disruption are undisclosed.
The group behind it: J
J is a ransomware group that operates by claiming to steal data from victims and then listing those organisations on a dedicated leak site. Like other actors in this category, it typically uses the threat of public release to pressure payment. Publicly documented activity by such groups often involves double-extortion tactics—combining encryption of systems with the threat of data publication—though specific prior campaigns attributed solely to J are not detailed in the available facts for this incident. In this case, the group’s listing of FAI Aviation Group and its description of the material as “the biggest leak ever” constitute claims made by the actor; they have not been independently verified in the reported information.
FAI Aviation Group and its sector
FAI Aviation Group is a global aviation service provider headquartered in Germany. It offers aircraft charter, aircraft management, air ambulance services and special-mission operations, and maintains a fleet of jets and helicopters. Industry descriptions place it among the larger aircraft operators in Europe. Organisations of this type routinely handle flight operations data, crew and passenger information, medical-transport records for air-ambulance work, contractual and financial documents, and technical details relating to aircraft maintenance and scheduling. A breach affecting such a provider can therefore touch both commercial operations and sensitive personal or medical information associated with specialised flights.
What was likely exposed
The only data type named in the available facts is “internal files” said to have been exfiltrated in the ransomware attack. No further breakdown—such as employee records, customer lists, medical manifests, financial documents or technical manuals—has been disclosed. The number of people affected is unknown. Aviation-service companies typically hold crew and passenger details, medical-transport documentation for air-ambulance missions, contracts, maintenance logs and operational schedules. Whether any of those categories were among the files claimed by J remains unconfirmed. The phrase “the biggest leak ever” appears only in the group’s own listing language and does not constitute verified evidence of scale or content.
Why it matters
If internal files were in fact taken, individuals whose personal, medical or travel-related information appeared in those files could face risks of identity misuse, targeted phishing or, in the case of air-ambulance patients, exposure of health details. For the organisation itself, unauthorised disclosure of operational or contractual material can create commercial, regulatory and reputational consequences, particularly in a sector that handles time-critical medical and special-mission flights. Because the precise contents and the number of affected people remain unknown, the concrete impact cannot yet be quantified; the risk is real but currently unmeasured.
What to do if you're exposed
Anyone who has worked with, flown with or received services from FAI Aviation Group should treat the possibility of exposure seriously until more information emerges. Monitor financial and medical accounts for unusual activity, enable multi-factor authentication on email and related services, and be alert to phishing messages that reference aviation or medical transport. Consider placing fraud alerts with credit-reporting agencies if personal identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official updates from the company or relevant authorities should be followed as they become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ikad.com.au - A 5-Month Staycation in the Defense Supply Chain Listed by J Ransomware Groupmulti-media systeme AG (mmsag.de) Listed by J Ransomware GroupJ. E. Stacey & Co. Ltd (jestacey.com) Listed by J Ransomware GroupPetro-Diamond (petrodiamond.com) - subsidiary of Mitsubishi Corporation Listed by J Ransomware GroupLatest breaches
Publicly posted by j — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.