HomeSecurityWestJet: Data Breach - Passport Leak

WestJet: Data Breach – Passport Leak

Canadian airline WestJet is notifying customers of a major data breach, after reviewing a cyberattack that took place in June that allowed attackers to steal sensitive travel documents — including passports and government IDs. The confirmation of the data breach ends a period of uncertainty since the incident was first announced on June 13.

WestJet data breach

WestJet – Cyberattack: What happened

In June, WestJet detected “suspicious activity” on its internal systems and temporarily suspended systems , the investigation continued in collaboration with external experts and authorities — the document states that the incident “involved access” to passenger data and that the FBI and other agencies are assisting in the investigation. The latest notification, sent on September 15 and shared in the US, includes the results of the recently completed analysis.

See also: APT35 hackers attack government and military organizations

Data Breach: What kind of data was exposed?

The alert describes a range of information that may have been stolen by the attackers: names, addresses, dates of birth, travel documents (passport/national ID), accommodation preferences, service requests, and even WestJet Rewards membership information. However, based on the investigation, payment card numbers, CVVs, and passwords were not exposed.

It took the company several months to complete its investigation into the data breach. While those confirmed to have been affected are being notified first, WestJet says recipients of the alert should inform others who may have flown under the same booking number as them, as their information may also have been exposed.

See also: Hackers approached BBC journalist for help in hack

WestJet: Data Breach - Passport Leak

Impact on travelers — Immediate protective steps

Customers who have been notified should immediately take precautionary measures: enroll in identity theft WestJet's bank account alerts , and monitor loyalty program activity. Additionally, those who shared government documents should consider possible passport/ID replacement procedures where applicable and report any suspicious use to appropriate authorities.

Legal, regulatory and operational implications

Public notices and the involvement of agencies like the FBI suggest that there will be compliance audits and potential legal requirements to notify customers and regulators in the countries where WestJet operates. Businesses that handle cross-border personal data should prepare impact reports, improve security SLAs with third parties, and maintain recovery plans that anticipate “breached backup” and customer communication scenarios.

The WestJet case is a reminder that attacks on travel infrastructure are not limited to service disruptions: they are about customer trust and identity management on a global scale.

See also: Asahi: Japan's largest brewery suffered a cyberattack

WestJet: Data Breach - Passport Leak

Airlines – Protection: Technology, education and transparency

Protecting against cyberattacks in the aviation sector requires a multi-layered approach:

  • Investments in cutting-edge cyber defense: Development of strong firewalls, threat detection through AI, data encryption and continuous network monitoring.
  • Staff training: Human factors are often the weakest link. Training in phishing, password management, and incident response is essential.
  • Regulatory compliance and transparency: Companies must comply with international cybersecurity regulations and maintain a transparent notification policy in cases of breaches.
  • Collaboration with authorities and other companies: Sharing information about threats and vulnerabilities strengthens collective defense.

See also: UK: Largest crypto seizure by authorities – Bitcoin Queen sentenced

As digital transformation continues at a rapid pace, airlines must address cybersecurity as a critical issue. It is not just a matter of technology, but of trust and survival. Protecting their networks is not a luxury — it is a prerequisite for safe, reliable and transparent air travel.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS