The Everest ransomware group has claimed responsibility for significant cyberattacks against Iberia, Spain's national airline, and Air Miles España, the operator of the Travel Club rewards program. In these incidents, Everest reportedly exfiltrated 596 GB of sensitive data from Iberia, including personal and payment information, loyalty details, travel histories, and booking-related communications for millions of customers across multiple countries. The attackers also claim to have had the ability to manipulate bookings, such as changing contact details, modifying seats, and cancelling tickets, posing a severe risk to passenger data security and operational integrity. For Air Miles España, Everest claims to have stolen approximately 131 GB of data and locked internal systems, following a double extortion model where files are both stolen and systems encrypted to pressure for ransom payment.
The breaches have raised significant concerns about identity theft, phishing, and regulatory compliance, particularly under GDPR, given the scale and sensitivity of the compromised data. The Everest group has threatened to leak the stolen information if negotiations with the affected organizations fail, a tactic consistent with their previous operations. The attacks highlight a growing trend of ransomware groups targeting high-profile entities in the travel and rewards sectors, with potential impacts extending to millions of individuals and business partners in Spain, Latin America, and other regions where Iberia and Travel Club operate.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC's Week 4 November 2025 roundup included the Everest incident, describing it as a data-exfiltration attack against Spain's largest airline. This was a follow-on report of the already disclosed Iberia event rather than a new incident.
Everest also claimed a separate attack on Air Miles España, operator of the Travel Club rewards program, alleging theft of about 131 GB of data and disruption of internal systems. The reportedly stolen information included personal and loyalty account data affecting customers and business partners.
The Everest ransomware group claimed it breached Iberia, Spain's national airline, and stole a large dataset reportedly including customer identity, loyalty, and payment information. Reports also said the group claimed it could manipulate bookings, raising risks for millions of customers across multiple countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.