Viva Air Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Viva Air Data Breach (2022) (reported March 14, 2022) exposed Email addresses, IP addresses, Names and Partial credit card data belonging to roughly 932K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
In March 2022, Viva Air suffered a data breach and subsequent ransomware attack. The incident resulted in the exposure of a transaction log containing 2.6 million entries linked to 932,000 unique email addresses. The reported data types include names, physical addresses, phone numbers, IP addresses, purchases, and partial credit card data showing only the last four digits.
Details on the precise intrusion method, the timeline of access, and any ransom demands or payments remain undisclosed in available reporting. The airline is now defunct.
Who is ransomexx?
RansomEXX is a ransomware group known for targeting mid-sized and large organizations across multiple sectors. The group typically employs double-extortion tactics, encrypting systems while also exfiltrating data for potential publication on a leak site if demands are not met.
Public reporting has linked the group to prior incidents involving healthcare providers, government agencies, and private companies. In this case, the attribution to RansomEXX rests on the group’s listing of Viva Air; that listing constitutes a claim by the group rather than an independently verified confirmation of every detail.
About Viva Air
Viva Air operated as a low-cost airline based in Colombia, serving domestic and international routes. Airlines routinely collect and store customer information to process bookings, manage loyalty programs, handle payments, and comply with regulatory requirements for passenger identification and security.
Such organizations maintain records that can span years of travel history. A breach at an airline therefore carries implications for large volumes of personal and transactional data accumulated through routine operations.
What was likely exposed
The reported incident exposed email addresses, names, physical addresses, phone numbers, IP addresses, purchase details, and partial credit card data limited to the last four digits. These elements were contained in a log of 2.6 million transactions affecting 932,000 unique email addresses.
Exact file contents, additional data fields, or the full scope of any other systems accessed have not been disclosed. Organizations in the airline sector commonly hold further categories of information such as passport details, frequent-flyer records, and full payment card numbers processed through secure channels; whether those were present in the exposed material remains unconfirmed.
Why it matters
Exposure of names, addresses, phone numbers, and email addresses can facilitate targeted phishing or social-engineering attempts. Partial credit card data, while incomplete, can still be combined with other information to increase the success rate of fraudulent transactions or account takeovers.
For the organization, the incident adds to operational and reputational consequences at a time when Viva Air was already moving toward closure. Affected individuals face the standard risks associated with the reuse of email addresses and contact details across multiple services.
If your data was in this breach
Review bank and credit card statements for any unauthorized activity and consider requesting new card numbers if the last four digits match records you hold. Use unique passwords for different accounts and enable multi-factor authentication where available. Monitor email inboxes for unsolicited messages that reference the exposed details.
Individuals can run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other publicly documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Vietnam Airlines Data Breach (2025)Kenya Airways Listed by ransomexx Ransomware GroupBadan Urusan Logistik Listed by ransomexx Ransomware GroupREC Silicon Listed by ransomexx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Viva Air Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.