WestJet, one of Canada’s largest airlines, confirmed that a cyberattack in June resulted in the exposure of sensitive customer information, including passports and government-issued identification documents. The incident disrupted certain internal systems and rendered the WestJet mobile app temporarily unavailable to users. WestJet’s internal cybersecurity teams, in coordination with law enforcement and Transport Canada, responded to the breach and worked to mitigate its impact. The company emphasized that operational safety was not compromised during the incident, and flight operations continued as normal. Impacted individuals received data breach notification letters outlining the types of personal information that may have been exposed, which varied by individual. Exposed data included names, dates of birth, mailing addresses, travel document details such as passport numbers, and information related to travel accommodations or complaints. For WestJet Rewards members, additional data such as membership ID numbers and points balances may have been compromised. The breach did not involve credit card or debit card numbers, expiry dates, CVV numbers, or account passwords, according to both the company’s statements and the notification letters. WestJet also clarified that information related to WestJet RBC Mastercard accounts was not affected. The company advised customers and employees to exercise increased caution when sharing personal information and to remain vigilant for potential phishing attempts. The breach notification recommended that customers inform others who may have traveled under the same booking, as their information could also be at risk. WestJet’s investigation into the incident concluded on September 15, and the company began notifying affected individuals shortly thereafter. While the Scattered Spider threat group was known to be targeting aviation organizations around the time of the breach, there has been no official attribution of the WestJet incident to any specific threat actor. WestJet has continued to update customers and authorities in both Canada and the United States as more information becomes available. The company is still working to determine the full scope of the breach and has committed to providing further notifications if additional individuals are found to be impacted. The incident highlights the ongoing risks faced by the aviation sector from sophisticated cyberattacks and the importance of robust data protection measures. WestJet’s response has focused on transparency, customer communication, and collaboration with regulatory authorities. The breach underscores the need for all organizations handling sensitive personal data to maintain strong cybersecurity defenses and incident response plans.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the disclosure, WestJet said the FBI, the Canadian Centre for Cyber Security, and the Office of the Privacy Commissioner of Canada were investigating the incident. The company also said it had notified relevant authorities and regulators.
By 2025-09-30, WestJet publicly disclosed that the summer 2025 cyberattack exposed personal information belonging to about 1.2 million individuals, including names, addresses, dates of birth, passport and government ID details, travel data, and some rewards-program information. The airline said affected people would receive 24 months or two years of identity monitoring and theft protection.
On 2025-09-15, WestJet said it determined that a sophisticated criminal third party had gained access to customer information during the June incident. The compromised data included personal and travel-related information, but not passwords or full payment card data.
Roughly five days after detecting the intrusion, WestJet restored impacted systems following containment and recovery efforts. The company also secured systems and began a forensic investigation.
On 2025-06-13, WestJet detected suspicious activity linked to a cyberattack, restricted access to some internal systems and its app, and engaged internal teams and external experts to respond. The airline later said flight operations were not put at risk.
6 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcescworld.com
Open sourcehackread.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.