
The Everest ransomware group says it compromised Iberia’s internal network, stealing close to 600GB of confidential information and issuing a $6 million ransom demand to the Spanish flag carrier.
Last week, in a data security incident notice sent to affected customers, Iberia said it recently learned of a security breach involving one of its service providers that resulted in the exposure of customers’ sensitive personal information.
An investigation revealed that the compromised data included full names, email addresses, Iberia Club loyalty card identification numbers, and other personal details. The airline added that no customer account access information, passwords, or full bank card details were exposed during the incident.
Iberia issued its data security incident notice about a week after a threat actor claimed on a hacking forum to have stolen roughly 77 gigabytes of data from the airline’s systems. The attacker said the trove was “extracted directly from the airline’s internal servers” and included A320/A321 technical documents, AMP maintenance files, engine data, and other internal records.
The threat actor also stated that they are willing to sell the entire stolen database for $150,000.
Recently, the Everest ransomware group said it had breached the internal systems of Iberia and stole 596 GB of data, including 430 GB of .eml files with more than 5 million records. The compromised data allegedly includes names, contact details, birthdates, travel and booking information, masked card data, and marketing profiles
🚨🚨Cyber Update ‼️
— Hackmanac (@H4ckmanac) November 26, 2025
🇪🇸Spain - Iberia
Everest hacking group is now demanding $6,000,000 from Iberia to prevent the data from being leaked.
Sector: Transportation / Storage
Threat class: Cybercrime
Status: Pending verification
—
About this post:
Hackmanac provides early… https://t.co/uoYzZSgqlp pic.twitter.com/iFJXT4vS9g
The hacking group has demanded a $6 million ransom from the airline and threatened to leak the stolen data if the payment is not made.
Iberia has not yet commented on Everest’s claims. It also remains unclear whether the two incidents are connected and part of a double-extortion attempt, or if the airline has actually experienced two separate security breaches.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543