Data Breaches

Payment Card Data Stolen in Air Europa Hack

Spanish airline Air Europa is informing customers that their payment card information has been stolen as a result of a hacker attack.

Spanish airline Air Europa is informing customers that their payment card information has been stolen as a result of a hacker attack.

Air Europa, one of Spain’s largest airlines, is urging some customers to cancel their payment cards after the information may have been compromised as a result of a recent hack. 

In notifications sent to impacted customers, the airline said it recently detected unauthorized access to a system storing payment card data. 

The company says hackers may have accessed partial credit card numbers, expiration dates, and CVV codes. No other information appears to have been compromised. 

Individuals who receive Air Europa’s email notifications are being advised to identify payment cards used to make purchases on its website, contact the associated bank, and request the card’s cancellation. They have also been advised to keep an eye out for any malicious phone calls, emails or messages. 

It’s unclear how many individuals are impacted, but the company said relevant authorities have been notified. 

It’s not uncommon for airlines to be targeted by ransomware groups, which often steal sensitive information from compromised systems. In this case, it’s also possible that Air Europa’s payment systems were targeted by cybercriminals who sell credit and debit card data on dark web marketplaces. 

Advertisement. Scroll to continue reading.

SecurityWeek has not seen any mention of Air Europa on the leak websites of major ransomware groups. 

The company has not responded to a request for additional information. 

Related: Cyberattack Steals Passenger Data From Portuguese Airline

Related: Breached American Airlines Email Accounts Abused for Phishing

Related: United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue

Related: American Airlines, Southwest Airlines Impacted by Data Breach at Third-Party Provider

Related Content

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Data Breaches

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Data Breaches

In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.

Data Breaches

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version