Wizz Air Listed by stormous Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Wizz Air was listed by the Stormous ransomware group on April 30, 2025, following the theft of internal files. Customers and staff should check official Wizz Air communications and consider changing passwords or enabling additional account protections.
On 30 April 2025 the ransomware group stormous listed Wizz Air on its leak site, claiming responsibility for a ransomware attack in which internal files were exfiltrated. The number of people affected has not been disclosed, and public information about the incident remains limited to the listing itself and a brief company statement.
Wizz Air responded that it maintains strong security systems designed to protect the sensitive data of customers and partners. The listing has drawn attention because the group asserts that the material has already circulated and been verified as linked to company employees, yet independent confirmation of the full scope is still absent.
Inside the incident
Public reporting on the matter begins with the stormous leak-site entry dated 30 April 2025. According to that listing, the group conducted a ransomware attack against Wizz Air and removed internal files. No further technical details—such as the initial access vector, the precise date of intrusion, the volume of data taken, or whether systems were encrypted—have been released by either the company or independent investigators. The number of individuals whose information may be involved is listed as unknown.
Wizz Air’s public response consists of a single sentence affirming the strength of its security controls. No timeline of detection, containment steps, or notification to regulators has been published. The group’s claim that the data has been widely circulated and verified as employee-related remains an unverified assertion; no sample files or independent forensic analysis have been made available in open sources to corroborate the scale or content of the alleged exfiltration.
The group behind it: stormous
Stormous is a ransomware operation that follows the now-familiar double-extortion model used by many contemporary groups. It typically gains access to a target network, exfiltrates selected data, encrypts systems, and then posts the victim’s name on a dedicated leak site if a ransom is not paid. The group has previously claimed attacks against organisations in multiple sectors, using the threat of public data release as leverage. Listings on its site are presented as proof of successful intrusion, yet they constitute claims rather than independently Reported Facts.
In this instance, stormous has asserted that internal files belonging to Wizz Air were taken and that the material has already been disseminated. No additional statements from the group—such as ransom demands, sample screenshots, or specific file counts—have been documented in public reporting connected to this particular listing. As with other ransomware claims, the presence of a name on a leak site does not by itself establish the accuracy or completeness of the group’s account.
About Wizz Air
Wizz Air is a Hungarian low-cost airline that operates an extensive network of short- and medium-haul routes across Europe and beyond. Like other carriers in the sector, it processes large volumes of passenger bookings, payment details, travel documents, and employee records. The company maintains customer-facing digital platforms for reservations, check-in, and account management, as well as internal systems supporting flight operations, crew scheduling, and corporate functions.
A breach involving an airline is consequential because the organisation routinely holds personally identifiable information of travellers and staff. Even when the precise data set remains unconfirmed, the mere possibility that internal files have left the company’s control raises legitimate concerns for anyone who has flown with or worked for the carrier. The aviation sector is also subject to regulatory obligations covering data protection and operational security, so any confirmed incident would typically trigger formal notifications and reviews.
What data was at risk
The only data type named in connection with the incident is “internal files exfiltrated in a ransomware attack.” No inventory of file names, categories, or record counts has been published. Public detail is therefore limited to the group’s claim that the material is valid and linked to employees.
Organisations of Wizz Air’s type ordinarily store passenger names, contact details, booking references, payment card information (often tokenised), passport or identity-document data for certain routes, and employee personnel files. Whether any of these categories were among the files allegedly taken remains unconfirmed. Until the company or an independent investigation provides a clearer description, the exact contents of the claimed data set cannot be stated as fact.
The real-world impact
For individuals, the primary risk is that personal or employment-related information could be used for targeted phishing, social-engineering attempts, or identity fraud. Even limited internal documents can contain enough context to make fraudulent communications appear legitimate. Employees whose details may have been included face the additional possibility of workplace-related scams or credential-stuffing attacks if login information was present.
For the organisation, the consequences centre on potential regulatory scrutiny, the cost of forensic investigation and remediation, and the need to reassure customers and partners. Operational disruption is also possible if systems were encrypted, although no public evidence of encryption has been released. Because the number of affected people is unknown and the data types remain unspecified, the practical scale of these risks cannot yet be quantified.
Were you affected?
If you have flown with Wizz Air, held an account on its website, or worked for the company, treat the listing as a prompt to review your exposure rather than as confirmed proof that your data was taken. Change passwords associated with any Wizz Air accounts, enable multi-factor authentication where available, and monitor bank and credit statements for unusual activity. Be alert to unsolicited emails or messages that reference recent travel or employment details.
You can also run a free exposure scan of your email address against known breach data sets to see whether your information has already appeared in other incidents. Such a check does not prove or disprove involvement in this specific event, but it provides a practical starting point for assessing broader risk and deciding whether further protective steps are warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
www.futureal.hu Listed by stormous Ransomware Groupwww.bkcolombia.org Listed by stormous Ransomware Groupwww.holidaypalace.com Listed by stormous Ransomware Groupwww.goodmanmfg.com Listed by stormous Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Wizz Air Listed by stormous Ransomware Group →
Publicly posted by stormous — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.