In late November 2025, Iberia Airlines disclosed a data breach resulting from unauthorized access to a third-party supplier’s systems. Iberia confirmed customer data exposure but stated its internal airline systems were not directly compromised.
Roughly one week prior to customer notifications, a threat actor advertised Iberia-related data for sale on hacking forums. The relationship between the advertised dataset and the confirmed customer breach remains unclear.
The situation was reported as contained, but the exposed data is now considered at-risk for misuse.
Iberia is Spain’s flag carrier and part of International Airlines Group (IAG), alongside British Airways, Aer Lingus, and Vueling. Iberia operates a global route network and manages millions of customer loyalty accounts through the Iberia Club program.
If you have:
Your information may be affected, even if you have not traveled recently.
This breach raises moderate-to-high phishing risk for affected customers.
Airline-related scams are highly effective due to urgency and travel stress.
Act defensively. Do not assume this is harmless.
Third-party vendor breaches are harder to detect and easier to underestimate. Loyalty identifiers and verified contact data are frequently chained into broader social engineering and account compromise campaigns.
If you are an ObscureIQ client, this breach can be checked against your active exposure profile. If not, a digital footprint audit can determine whether your data appears in this incident or related datasets already circulating.
This breach is contained operationally.
The data risk is not.
If you believe your information may be part of this breach,or want confirmation across other datasets,