The ransomware group The Crew posted Cyprus Airways , the state-owned airline of Cyprus, on its dark web leak site on August 24, 2026. This is just a claim , and the listing itself is not proof that an attack has taken place — it could be true, it could be recycled data from an earlier incident by another group, it could be exaggerated, or it could be completely fake . The claim was originally spotted by GalaxyWarden Threat Research based on RansomLook data.

Cyprus Airways has not confirmed the incident, has not made an official announcement, nor has a relevant update been issued by the Cypriot Data Protection Commissioner. No independent source has verified the claim so far. SecNews publishes the news because it concerns critical infrastructure in Cyprus, but with a clear caveat: no attack should be discounted.
See also: Medochemie: Qilin ransomware claims attack on Cypriot pharmaceutical company
What exactly does the claim say?
The entry of Cyprus Airways on The Crew’s leak site, dated August 24, 2026, is unsupported by any supporting evidence. No sample of stolen files is published, no date is stated for when the alleged attack took place, no details are given of how many people were potentially affected, and no categories of data are specified. The group limits itself to a general statement that it allegedly gained access to “internal data” of the airline.
The Recent Breaches database classifies the severity as HIGH, but with an explicit marking: “unverified claim, pending independent verification”. The SecNews technical team emphasizes that such listings are often used by ransomware groups as a publicity or pressure tactic, regardless of whether there is an actual incident in the background. Until evidence is presented, the claim remains just that: a claim, not a confirmed incident.

Why ransomware group claims aren't always true
The ransomware industry has evolved into an ecosystem where publicity is almost as important as actual incidents. Groups looking to build a reputation or pressure victims into paying often publish company names without any evidence. The most common cases are: recycling past incidents of another group as their own, publishing names with completely fabricated backgrounds for publicity, or exaggerating the volume and severity of a real but limited access.
According to GalaxyWarden, ransomware group claims are described as “marketing, not audited evidence”. For this reason, serious threat intelligence organizations always separate unconfirmed claims from actual confirmed incidents. In the case of Cyprus Airways, we are still in the first category and any discussion of the extent of damage is premature.
Older claim from 2025 — also unconfirmed
In June 2025, a different group of cybercriminals posted on an online forum an alleged claim that they had 41 GB of Cyprus Airways passenger data, as reported by Cybernews. The claim at the time covered data from 2018 to June 2025, with 1.5 million Passenger Name Records (PNRs) and 2.3 million e-tickets. The Cybernews research team had examined the sample and considered that some of it appeared genuine, but the airline has not publicly confirmed the incident.
It's unclear whether The Crew's new listing is from the same data source, a new separate incident, or a recycling of older alleged material from a different group. An official position on the previous 2025 incident is also pending — making it difficult to clearly distinguish between the two cases.
See also: Medusa Ransomware: New victims in critical infrastructure
Who is The Crew ransomware group?
The Crew is a relatively new ransomware group, with GalaxyWarden tracking six cases it has reportedly posted on its leak site so far. On August 24, 2026, the group simultaneously uploaded three organizations: Cyprus Airways, KBZ Bank (a Myanmar banking entity), and a database it describes as an “Indonesian Police Officers Database.” The common publication date suggests either a coordinated publicity effort or a batch of claims with no common ground.
The Crew’s postings so far are characterized by a lack of technical details: no indicators of compromise (IoCs), malware samples, file hashes, or specific targets are provided. This differentiates the group from more “mature” ransomware operations like Qilin or LockBit, which typically publish detailed information when they actually have stolen material. The Crew’s strategy is closer to making claims without verification — which reinforces the need for caution.
Preventive measures as a general practice
Even if The Crew’s claim proves to be untrue, general passenger safety hygiene remains important. The SecNews editorial team recommends — as a general practice, not in response to a confirmed incident — to be wary of suspicious emails impersonating airlines with offers, refunds, or requests to update information. Verifying any communication through the company’s official channels is always the first step.
At the same time, those who use the same password on multiple platforms must change it and activate two-factor authentication (2FA) on email accounts and banking services. These measures always apply, regardless of whether a specific claim is true or not. The Personal Data Protection Commissioner of Cyprus is the competent body if a citizen believes that their personal data has been exposed.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Regulatory obligations — only if confirmation occurs
As the national airline, Cyprus Airways will be subject to strict information security obligations if an actual incident is proven to have occurred. The NIS2 classifies the aviation sector as critical infrastructure, with an obligation to report serious incidents within 24 hours of becoming aware of them. At the same time, the GDPR requires notification within 72 hours of personal data breaches that pose a risk to data subjects.
The absence of such an announcement may mean that the company is still investigating the allegation, that it considers it unfounded, or that it does not meet the disclosure criteria. One of the first signs of whether there is a real basis will be the movement of the relevant Cypriot authorities in the coming days.
What should we watch?
Two developments will determine whether The Crew’s claim is upgraded to a confirmed incident. First, if the team publishes a sample of stolen data on its leak site in the coming days — a common tactic as a final warning. Second, if Cyprus Airways issues an official statement, either publicly or to regulators. If neither happens, the case will remain in the category of unconfirmed allegations — and should be treated as such.
The SecNews editorial team is monitoring the case and will update as soon as evidence or an official announcement from the company emerges. Whistleblowers with additional information can contact us anonymously via the report.secnews.gr — no identity, IP or metadata is recorded on the platform.
