Company Details
air-canada
23,646
712,303
481
aircanada.com
0
AIR_3095438
In-progress


Air Canada Company CyberSecurity Posture
aircanada.comCanada's largest airline, the country’s flag carrier and a founding member of Star Alliance, the world's most comprehensive air transportation network celebrating its 25thanniversary in 2022, Air Canada provides scheduled passenger service directly to 51 airports in Canada, 51 in the United States and 86 internationally. It is the only international network carrier in North America to receive a Four-Star ranking from Skytrax, which in 2021 gave Air Canada awards for the Best Airline Staff in North America, Best Airline Staff in Canada, Best Business Class Lounge in North America, and an excellence award for its management of the COVID-19 pandemic. ** Air Canada est la plus importante société aérienne du Canada, le transporteur national du pays et un membre cofondateur du réseau Star Alliance — le plus vaste regroupement mondial de sociétés aériennes, qui célèbre son 25e anniversaire en 2022. Les lignes passagers régulières d’Air Canada relient sans escale 51 aéroports au Canada, 51 aux États-Unis et 86 sur le reste du globe. En Amérique du Nord, Air Canada constitue le seul transporteur aérien d’envergure internationale offrant une gamme complète de services à détenir la cote quatre étoiles de Skytrax qui, en 2021, lui a décerné les prix Meilleur personnel au sol et à bord en Amérique du Nord, Meilleur personnel au sol et à bord au Canada, Meilleur salon de classe affaires en Amérique du Nord ainsi qu’un Prix d’excellence pour sa gestion de la pandémie de la COVID-19.
Company Details
air-canada
23,646
712,303
481
aircanada.com
0
AIR_3095438
In-progress
Between 700 and 749

Air Canada Global Score (TPRM)XXXX

Description: In a recent breach, threat actors gained access to some employees' personal information, according to Air Canada, the country's largest and flag carrier. An unauthorized organization temporarily gained restricted access to an internal Air Canada system pertaining to restricted personal data of some workers and specific records. No customer data was accessed. according to the company's statement that was released. A system inside the business was accessible to the attackers. The airline informed the concerned staff members and the appropriate authorities.


No incidents recorded for Air Canada in 2026.
No incidents recorded for Air Canada in 2026.
No incidents recorded for Air Canada in 2026.
Air Canada cyber incidents detection timeline including parent company and subsidiaries

Canada's largest airline, the country’s flag carrier and a founding member of Star Alliance, the world's most comprehensive air transportation network celebrating its 25thanniversary in 2022, Air Canada provides scheduled passenger service directly to 51 airports in Canada, 51 in the United States and 86 internationally. It is the only international network carrier in North America to receive a Four-Star ranking from Skytrax, which in 2021 gave Air Canada awards for the Best Airline Staff in North America, Best Airline Staff in Canada, Best Business Class Lounge in North America, and an excellence award for its management of the COVID-19 pandemic. ** Air Canada est la plus importante société aérienne du Canada, le transporteur national du pays et un membre cofondateur du réseau Star Alliance — le plus vaste regroupement mondial de sociétés aériennes, qui célèbre son 25e anniversaire en 2022. Les lignes passagers régulières d’Air Canada relient sans escale 51 aéroports au Canada, 51 aux États-Unis et 86 sur le reste du globe. En Amérique du Nord, Air Canada constitue le seul transporteur aérien d’envergure internationale offrant une gamme complète de services à détenir la cote quatre étoiles de Skytrax qui, en 2021, lui a décerné les prix Meilleur personnel au sol et à bord en Amérique du Nord, Meilleur personnel au sol et à bord au Canada, Meilleur salon de classe affaires en Amérique du Nord ainsi qu’un Prix d’excellence pour sa gestion de la pandémie de la COVID-19.


People. Passion. Pride. These have driven our team since 1833. Since that time, we have developed to become a critical partner in the global aviation industry, delivering time-critical logistics services at over 350 locations in 65 countries, across six continents. But at the heart of our

Turkish Airlines has soared to new heights since its first flight in 1933, becoming the airline that connects more countries than any other. Our commitment to excellence is reflected in the world-class service, comfort, and innovative travel experience we offer, designed to elevate every journey.
We would like to acknowledge the Traditional Custodians of the local lands and waterways on which we live, work and fly. We pay our respects to Elders past and present. Spirit is everything to us, and joining the Qantas team means bringing your spirit to ours. We have over 29,000 exceptional emplo

Delta Air Lines (NYSE: DAL) is the U.S. global airline leader in safety, innovation, reliability and customer experience. Powered by our employees around the world, Delta has for a decade led the airline industry in operational excellence while maintaining our reputation for award-winning customer s

We’re on a mission to make low-cost travel easy. Whatever your role, you’ll connect millions of people to what they love using Europe’s best airline network, great value fares, and friendly service. And to help us get there we’ll give you everything you need to make a personal impact on our growing
We’re creating an airline people love. It begins with each Alaska Airlines employee, bringing unique strengths and energy to our work in the air and on the ground. Every day, we go beyond what’s expected and reach for the remarkable, together. Welcome to our LinkedIn page. We like conversations on
Qatar Airways is the national airline of the State of Qatar. Based in Doha, the Airline’s trendsetting on-board product focuses on: comfort, fine cuisine, the latest in-flight audio & video entertainment, award-winning service and one of the youngest and most advanced aircraft fleet in the sky. Awa
At Southwest®, everything we do—from our smiling People to our policies—is designed to let you go with Heart. No matter what comes up in your travels, we’ve got your back. Because while any airline can fly you, only Southwest lets you go with Heart. Application fees don’t fly. The only way to apply

Marhaba! Welcome to Etihad Airways. We are proud to be the national airline of the UAE, flying to 100+ destinations via Abu Dhabi. At Etihad, we don't stop at the border of what's possible, we go beyond it. Proudly inspired by our Emirati identity, we are dedicated to delivering extraordinary trave
.png)
Inside Tom Levasseur's CyberSci program and the hands-on revolution in cybersecurity education.
COMMENTARY: It took only six months after the emergence of ChatGPT for a new class of incidents to emerge. The first well-publicized...
CrowdStrike catches insider selling data, Spanish airline Iberia suffers breach and data leak, AI is too risky to insure, say insurers.
VANCOUVER - Telus Corp. is launching a new cybersecurity service meant to protect businesses from future digital threats related to quantum...
Discover the Airbus A220: a clean-sheet design single-aisle aircraft offering quiet comfort, fuel efficiency, and unmatched performance.
Professor Kash Khorasani's project receives $2 million from the National Cybersecurity Consortium.
Director General of Indian Computer Emergency Response Team CERT-In, Dr. Sanjay Bahl, has said India's Cybersecurity Ecosystem scaled new...
Envoy Air joins Qantas, Aeroflot, and Vietnam Airlines in facing the worst cybersecurity breach of 2025. This massive cyberattack has shaken...
WestJet is introducing fixed-recline seats in economy on some planes, meaning the seats won't recline.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Air Canada is http://www.aircanada.com/careers.
According to Rankiteo, Air Canada’s AI-generated cybersecurity score is 735, reflecting their Moderate security posture.
According to Rankiteo, Air Canada currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Air Canada has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Air Canada is not certified under SOC 2 Type 1.
According to Rankiteo, Air Canada does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Air Canada is not listed as GDPR compliant.
According to Rankiteo, Air Canada does not currently maintain PCI DSS compliance.
According to Rankiteo, Air Canada is not compliant with HIPAA regulations.
According to Rankiteo,Air Canada is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Air Canada operates primarily in the Airlines and Aviation industry.
Air Canada employs approximately 23,646 people worldwide.
Air Canada presently has no subsidiaries across any sectors.
Air Canada’s official LinkedIn profile has approximately 712,303 followers.
Air Canada is classified under the NAICS code 481, which corresponds to Air Transportation.
Yes, Air Canada has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/air-canada.
Yes, Air Canada maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/air-canada.
As of January 25, 2026, Rankiteo reports that Air Canada has experienced 1 cybersecurity incidents.
Air Canada has an estimated 3,672 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an law enforcement notified with yes, and communication strategy with informed concerned staff members and appropriate authorities..
Title: Air Canada Data Breach
Description: Unauthorized access to an internal Air Canada system resulted in the exposure of some employees' personal information.
Type: Data Breach
Attack Vector: Unauthorized access to internal system
Threat Actor: Unknown
Motivation: Unspecified
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Employees' personal information
Systems Affected: Internal Air Canada system
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Employees' personal information.

Entity Name: Air Canada
Entity Type: Airline
Industry: Aviation
Location: Canada
Size: Large
Customers Affected: None

Law Enforcement Notified: Yes
Communication Strategy: Informed concerned staff members and appropriate authorities

Type of Data Compromised: Employees' personal information
Personally Identifiable Information: Yes

Source: Air Canada
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Air Canada.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Informed concerned staff members and appropriate authorities.
Last Attacking Group: The attacking group in the last incident was an Unknown.
Most Significant Data Compromised: The most significant data compromised in an incident was Employees' personal information.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Employees' personal information.
Most Recent Source: The most recent source of information about an incident is Air Canada.
.png)
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.