TAP Air Portugal Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The TAP Air Portugal Data Breach (2022) (reported August 25, 2022) exposed Dates of birth, Email addresses, Genders and Names belonging to roughly 6.1M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In August 2022, Portuguese airline TAP Air Portugal was hit by a ransomware attack that led to the exposure of personal data belonging to about 6.1 million people. Public reporting dated 25 August 2022 states that the attackers later published the compromised material on a dark-web leak site. More than five million unique email addresses appeared in the material, together with names, dates of birth, genders, nationalities, phone numbers, physical addresses and salutations. For passengers, employees and others whose details sat in the airline’s systems, the incident raised concrete questions about how the data might be misused and what steps they should take next.
The scale and the types of information involved make the event consequential even though many operational details remain limited in public accounts. What follows draws only on the What's Publicly Reported of the case and on general knowledge of how airlines handle customer data and how ransomware incidents typically unfold.
What happened
According to contemporaneous reports, TAP Air Portugal became the target of a ransomware attack in August 2022. The activity was attributed to the Ragnar Locker group, which subsequently posted the stolen data on a publicly accessible dark-web site. The disclosed material encompassed records linked to roughly 6.1 million individuals. Among the exposed fields were more than five million unique email addresses, along with names, genders, dates of birth, nationalities, phone numbers, physical addresses and salutations.
Public detail does not describe the precise initial access method, the duration of the intrusion, or the full technical scope of systems affected. The known facts centre on the ransomware nature of the attack, the subsequent leak-site publication, and the categories of personal data that appeared in the released files. No further breakdown of affected customer versus employee populations, or of any ransom demand or payment, has been supplied in the available record.
How a breach like this happens
Ransomware incidents of this general type usually begin when an attacker gains a foothold inside an organisation’s network. Common entry routes include phishing messages that trick a user into running malicious code, exploitation of unpatched remote-access services, or stolen credentials obtained from earlier breaches or infostealer malware. Once inside, the operators often move laterally, elevating privileges and locating file servers, databases or backup repositories that hold large volumes of personal or operational data.
After the data of interest has been copied, the attackers typically encrypt systems or threaten to do so, then demand payment. In many cases they also prepare a public leak site and release samples or full archives if negotiations stall or as additional pressure. The presence of a dark-web dump does not by itself prove every record is accurate or complete, but it does place the material in circulation where other criminals can obtain and reuse it. None of these steps requires naming a particular group beyond what has already been reported for this incident; they simply describe the pattern repeatedly observed in ransomware campaigns against large enterprises.
TAP Air Portugal and its sector
TAP Air Portugal is the flag-carrier airline of Portugal, operating passenger and cargo flights across Europe, Africa, North America and other regions. Like any major carrier, it maintains extensive digital records to manage bookings, loyalty programmes, check-in, crew scheduling and regulatory compliance. Those systems routinely store passenger names, contact details, travel documents, payment references and demographic information needed for security and customs processes.
Airlines sit at the intersection of high passenger volumes and strict identity requirements. A single reservation can link an email address and phone number to a date of birth, nationality and home address. When such collections are compromised, the consequences extend beyond the company itself: travellers may face targeted fraud, and the carrier must manage regulatory notifications, customer trust and potential operational disruption. The 2022 incident therefore sits within a broader pattern of ransomware pressure on transportation and travel firms that hold large, structured stores of personal data.
What data was at risk
The facts identify the following categories as exposed: dates of birth, email addresses, genders, names, nationalities, phone numbers, physical addresses and salutations. Reporting also notes that more than five million unique email addresses were among the material released. These fields match the kinds of biographical and contact information airlines typically retain for ticketing, communication and border-control purposes.
Public accounts do not confirm whether additional elements—such as passport numbers, payment-card data, frequent-flyer credentials or internal employee records—were present in the leaked set. Because those details are unconfirmed, they cannot be treated as established facts of this breach. What is known is limited to the named personal-data types and the overall count of roughly 6.1 million affected individuals.
What's at stake
For individuals, the combination of name, date of birth, address, phone number and email creates a ready-made package for phishing, social-engineering calls and account-takeover attempts. Fraudsters can craft convincing messages that reference a real flight or a plausible airline interaction. Nationality and gender data can further refine targeting. Even without financial credentials in the confirmed set, the exposed contact and identity details raise the risk of long-term identity misuse or credential stuffing against other online services where the same email and password combinations may have been reused.
For the airline, the incident carries regulatory, reputational and operational costs. Passenger trust is harder to rebuild once personal data has circulated on a leak site. Notification duties, potential fines under data-protection rules, and the expense of forensic investigation and system hardening all follow. The broader travel sector also absorbs indirect effects when customers become more cautious about sharing information or using digital channels.
What to do if you're exposed
If you have flown with TAP Air Portugal or otherwise supplied personal details to the airline before August 2022, treat the named data types as potentially circulating. Change passwords on any accounts that share the exposed email address, and enable multi-factor authentication wherever it is offered. Be alert to unsolicited messages or calls that reference flights, refunds or account problems; verify such contacts through official channels rather than links or numbers supplied in the message itself. Monitor financial statements and consider a fraud alert with credit agencies if you notice suspicious activity.
You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. That step provides an additional signal about the wider circulation of your information and helps prioritise further protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RailYatri Data Breach (2022)Gemini Data Breach (2022)SevenRooms Data Breach (2022)Activision Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the TAP Air Portugal Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.