Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Envoy Air

Envoy Air Vendor Cyber Rating & Cyber Score

envoyair.com

Envoy Air Inc. is a wholly-owned subsidiary of American Airlines Group (NASDAQ: AAL) operating more than 160 aircraft on 875 daily flights to over 160 destinations. The company’s more than 20,000 employees provide regional flight service to American Airlines under the American Eagle brand and livery and Ground-handling services for many American flights. Connect with Envoy on X @EnvoyAirCareers, on Instagram @EnvoyAirCareers, and on Facebook at Facebook.com/envoyaircareers and Facebook.com/EnvoyPilotRecruitment.


Envoy Air A.I CyberSecurity Scoring

Envoy Air
Company Information
Website:https://envoyair.com
Employees number:7,139
Number of followers:78,583
NAICS:481
Industry Type:Airlines and Aviation
Homepage:envoyair.com
Envoy Air Risk Score (AI oriented)
Between 0 and 549
logo
Envoy AirAirlines and Aviation
Updated:
03/04/2026
219/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Envoy Air Global Score (TPRM)
xxxx
logo
Envoy AirAirlines and Aviation
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Envoy Air
Envoy AirCritical
Current Score
219C (CRITICAL)
01000
5 incidents
-131 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
248Before Incident
MAY 2026
229Before Incident
APRIL 2026
229Before Incident
MARCH 2026
209Before Incident
FEBRUARY 2026
207Before Incident
JANUARY 2026
197Before Incident
DECEMBER 2025
176Before Incident
NOVEMBER 2025
172Before Incident
OCTOBER 2025
329Before Incident
Ransomware
20 Oct 2025Envoy Air
Envoy Air

Envoy Air Oracle System Breach Following Clop Extortion Claims

157After Incident
CRITICAL-172
ENV1432914102025
Envoy Air, a regional airline subsidiary of American Airlines, disclosed a breach in its Oracle E-Business Suite system. The incident was linked to the Clop ransomware gang, which listed American Airlines on its data leak site, suggesting the compromise involved extortion threats. While the exact scope of the breach remains undisclosed, the involvement of Clop—a notorious ransomware group known for data exfiltration and extortion—implies potential exposure of sensitive corporate or employee data. The attack targeted a critical enterprise system (Oracle E-Business Suite), which typically manages financial, HR, and operational data, raising concerns about financial fraud, reputational damage, or regulatory penalties. Envoy Air has not confirmed whether customer data was affected, but the association with Clop increases the likelihood of internal data leaks or operational disruptions. The breach underscores vulnerabilities in third-party enterprise software and the escalating risks posed by ransomware-as-a-service (RaaS) groups like Clop.
INCIDENT DETAILS -
TYPE
data breachransomware
MOTIVATION
extortion
IMPACT
Oracle E-Business Suite
SEPTEMBER 2025
512Before Incident
Ransomware
01 Sep 2025Envoy Air
Envoy Air

Envoy Air Ransomware Attack via Oracle E-Business Suite Zero-Day Vulnerability (CVE-2025-61882)

309After Incident
MEDIUM-203
ENV5932059102125
Texas-based regional airline Envoy Air, a subsidiary of American Airlines, confirmed a breach on October 17, 2025, stemming from a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS), exploited by the CL0P ransomware group (TA505/FIN11). The attack was part of a coordinated extortion campaign targeting global companies via a high-volume email phishing scheme launched in late September 2025. While Envoy Air stated that no sensitive customer data or flight operations were affected, the breach compromised limited business information and commercial contact details.The vulnerability allowed attackers to gain unauthorized remote access without credentials, and Oracle released an emergency patch on October 4, 2025, after nearly three months of active exploitation. CL0P had already listed American Airlines (Envoy Air’s parent company) on their dark web leak site on October 16, 2025, claiming significant data theft. Experts warned of a ripple effect across organizations using Oracle EBS, emphasizing urgent patching to mitigate the threat.
INCIDENT DETAILS -
TYPE
ransomwaredata breachzero-day exploit
MOTIVATION
financial extortiondata theft for leverage
IMPACT
limited business informationcommercial contact detailsOracle E-Business Suite (EBS)Operational Impact: none (no impact on flight or airport operations)Brand Reputation Impact: potential reputational risk due to association with CL0P and parent company (American Airlines) listing on dark webIdentity Theft Risk: none (no sensitive customer data affected)Payment Information Risk: none
DATA BREACH
business informationcommercial contact detailsSensitivity Of Data: low (no sensitive customer or operational data)Personally Identifiable Information: none
AUGUST 2025
512Before Incident
JULY 2025
517Before Incident
Cyber Attack
01 Jul 2025Envoy Air
Envoy Air Hit With Class Suit Over Oracle ‘Hub and Spoke’ Breach

Envoy Air and Oracle Data Breach Lawsuit

499After Incident
CRITICAL-18
ENV1765565536
Former Envoy Air Employee Sues Over 2025 Data Breach Linked to CL0P Ransomware Group A former Envoy Air Inc. employee has filed a class-action lawsuit against the regional airline and Oracle Corp., alleging negligence in protecting sensitive employee data exposed during a July 2025 cyberattack. The breach, attributed to the CL0P ransomware group, compromised personal information stored in Oracle’s business-software system, including Social Security numbers, birth dates, and financial account details. Khianna Parks, the plaintiff, seeks to represent current and former Envoy Air employees affected by the incident. The complaint was filed on Wednesday in the U.S. District Court for the Western District of Texas. Envoy Air, a subsidiary of American Airlines Group Inc., has not yet publicly responded to the allegations. The lawsuit highlights growing concerns over third-party vendor security risks and the persistent threat posed by ransomware groups targeting enterprise software systems. The breach underscores the potential long-term consequences of exposed personal data, including identity theft and financial fraud.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Personal information (Social Security numbers, birth dates, financial account information)Systems Affected: Oracle’s business-software systemBrand Reputation Impact: Likely negativeLegal Liabilities: Lawsuit filedIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Social Security numbersBirth datesFinancial account informationSensitivity Of Data: HighPersonally Identifiable Information: Yes
JUNE 2025
669Before Incident
Ransomware
16 Jun 2025Envoy Air
Envoy Air (MQ)

Envoy Air Oracle E-Business Suite Data Breach Linked to Clop Ransomware

514After Incident
MEDIUM-155
ENV1802118101925
Envoy Air, a regional subsidiary of American Airlines, confirmed a cybersecurity breach linked to the Clop ransomware group, which exploited a zero-day vulnerability (CVE-2025-61882) in its Oracle E-Business Suite. The attack was part of a broader global campaign targeting multiple organizations. While the breach exposed business and commercial contact data, Envoy Air clarified that no sensitive customer or financial information was compromised. The Clop group leaked stolen data on its dark web platform, accusing the airline of neglecting cybersecurity. The incident follows a pattern of Clop’s large-scale data exfiltration operations, leveraging unpatched vulnerabilities in enterprise systems. Envoy Air engaged law enforcement and initiated an investigation, but the breach underscores ongoing risks in third-party enterprise applications, particularly in the aviation sector. The attack did not disrupt operations but raised concerns about supply-chain vulnerabilities and the exposure of non-sensitive corporate data to malicious actors.
INCIDENT DETAILS -
TYPE
Data BreachRansomware Extortion
MOTIVATION
Financial GainData TheftExtortion
IMPACT
Business DataCommercial Contact DataOracle E-Business SuiteBrand Reputation Impact: Potential reputational damage due to dark web data leak and public disclosure by ClopIdentity Theft Risk: None (no sensitive customer or financial data compromised)Payment Information Risk: None
DATA BREACH
Business DataCommercial Contact InformationSensitivity Of Data: Low (no PII or financial data)
MAY 2025
767Before Incident
Ransomware
01 May 2025Envoy Air
Envoy Air

Cyberattack on Envoy Air via Oracle E-Business Suite Vulnerability

666After Incident
HIGH-101
ENV1533115102225
Envoy Air, a subsidiary of American Airlines, fell victim to a cyberattack executed by the Cl0p ransomware group, exploiting a vulnerability in Oracle E-Business Suite applications. While the company confirmed that no sensitive or customer data was compromised, a limited amount of business information and commercial contact details may have been exposed. The attack was part of a broader campaign targeting Oracle’s widely used enterprise software, affecting multiple organizations globally. Envoy Air is actively investigating the incident in coordination with law enforcement. Experts warn that the exploitation window—spanning nearly three months (July to October 2025)—allowed threat actors to exfiltrate large volumes of data from unpatched systems. The attack underscores risks tied to third-party dependencies, operational disruptions, and potential long-term erosion of public trust. Google’s threat intelligence suggests over 100 organizations could be impacted, with many possibly unaware of their compromise during the zero-day period. Patches for the vulnerabilities (CVE-2025-61882, CVE-2025-61884) were released in October 2025, but delayed mitigation may have exacerbated exposure.
INCIDENT DETAILS -
TYPE
CyberattackRansomwareData Breach
MOTIVATION
Financial GainData ExfiltrationDisruption
IMPACT
Business InformationCommercial Contact DetailsOracle E-Business Suite ApplicationsDisruption of OperationsResource StrainInvestigation OverheadErosion of Public Trust
DATA BREACH
Business InformationCommercial Contact DetailsLow (No Sensitive or Customer Data Confirmed)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Envoy Air ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Envoy Air's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Envoy Air's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Envoy Air ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Envoy Air's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?