Data Breaches

1.2 Million Impacted by WestJet Data Breach

The Canadian airline fell victim to a cyberattack in June and has completed the analysis of stolen information.

WestJet data breach

Canadian airline WestJet is notifying roughly 1.2 million people that their personal information was stolen in a June 2025 cyberattack.

The Alberta, Canada-based company was hit on June 13, with the cyberattack impacting the availability of its application and website.

This week, the company confirmed that personal information was stolen in the attack, and notified the Maine Attorney General’s Office that 1.2 million individuals were affected.

The stolen information includes names, addresses, dates of birth, government-issued ID details, and other information that customers shared in relation to their travel needs, including accommodation requests and complaints.

For WestJet Rewards members, membership details, such as WestJet Rewards ID number and points balance, and other account information may have been compromised as well.

For WestJet RBC Mastercard, RBC World Elite Mastercard, and RBC World Elite Mastercard for Business cardholders, information such as credit card identifier type and changes to point balance might have been affected as well.

Advertisement. Scroll to continue reading.

“To the extent that any of your travel information is linked to other individuals (such as family members or others travelling under the same booking number), you may wish to make them aware of the incident,” the company told the affected individuals.

The airline is providing the impacted individuals with 24 months of free monitoring, identity theft protection, and proactive fraud assistance services, which include up to $1 million of expense reimbursement insurance.

“Importantly, credit card or debit card numbers, expiry dates and CVV numbers, and guest user passwords, were not compromised, and our systems are fully secure,” WestJet says.

WestJet did not disclose the nature of the cyberattack and is unclear if the hackers attempted to extort the company. SecurityWeek has not seen any known ransomware groups claiming the incident.

Related: 766,000 Impacted by Data Breach at Dealership Software Provider Motility

Related: Cybercriminals Claim Theft of Data From Oracle E-Business Suite Customers

Related: 1.5 Million Impacted by Allianz Life Data Breach

Related: Cybersecurity Awareness Month 2025: Prioritizing Identity to Safeguard Critical Infrastructure

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version