Envoy Air A.I CyberSecurity Scoring
Envoy Air
Company Information
Website:https://envoyair.com
Employees number:7,139
Number of followers:78,583
NAICS:481
Industry Type:Airlines and Aviation
Homepage:envoyair.com
Envoy Air Risk Score (AI oriented)
Between 0 and 549
Envoy AirAirlines and Aviation
Updated:
03/04/2026
03/04/2026
219/1000
Critical
C
Envoy Air Global Score (TPRM)
xxxx
Envoy AirAirlines and Aviation
Score locked

Envoy AirCritical
Current Score
219C (CRITICAL)
01000
5 incidents
-131 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
248
MAY 2026
229
APRIL 2026
229
MARCH 2026
209
FEBRUARY 2026
207
JANUARY 2026
197
DECEMBER 2025
176
NOVEMBER 2025
172
OCTOBER 2025
329
Ransomware
20 Oct 2025 • Envoy Air
Envoy Air
Envoy Air Oracle System Breach Following Clop Extortion Claims
157
CRITICAL-172
ENV1432914102025
Envoy Air, a regional airline subsidiary of American Airlines, disclosed a breach in its Oracle E-Business Suite system. The incident was linked to the Clop ransomware gang, which listed American Airlines on its data leak site, suggesting the compromise involved extortion threats. While the exact scope of the breach remains undisclosed, the involvement of Clop—a notorious ransomware group known for data exfiltration and extortion—implies potential exposure of sensitive corporate or employee data. The attack targeted a critical enterprise system (Oracle E-Business Suite), which typically manages financial, HR, and operational data, raising concerns about financial fraud, reputational damage, or regulatory penalties. Envoy Air has not confirmed whether customer data was affected, but the association with Clop increases the likelihood of internal data leaks or operational disruptions. The breach underscores vulnerabilities in third-party enterprise software and the escalating risks posed by ransomware-as-a-service (RaaS) groups like Clop.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
SEPTEMBER 2025
512
Ransomware
01 Sep 2025 • Envoy Air
Envoy Air
Envoy Air Ransomware Attack via Oracle E-Business Suite Zero-Day Vulnerability (CVE-2025-61882)
309
MEDIUM-203
ENV5932059102125
Texas-based regional airline Envoy Air, a subsidiary of American Airlines, confirmed a breach on October 17, 2025, stemming from a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS), exploited by the CL0P ransomware group (TA505/FIN11). The attack was part of a coordinated extortion campaign targeting global companies via a high-volume email phishing scheme launched in late September 2025. While Envoy Air stated that no sensitive customer data or flight operations were affected, the breach compromised limited business information and commercial contact details.The vulnerability allowed attackers to gain unauthorized remote access without credentials, and Oracle released an emergency patch on October 4, 2025, after nearly three months of active exploitation. CL0P had already listed American Airlines (Envoy Air’s parent company) on their dark web leak site on October 16, 2025, claiming significant data theft. Experts warned of a ripple effect across organizations using Oracle EBS, emphasizing urgent patching to mitigate the threat.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
512
JULY 2025
517
Cyber Attack
01 Jul 2025 • Envoy Air
Envoy Air Hit With Class Suit Over Oracle ‘Hub and Spoke’ Breach
Envoy Air and Oracle Data Breach Lawsuit
499
CRITICAL-18
ENV1765565536
Former Envoy Air Employee Sues Over 2025 Data Breach Linked to CL0P Ransomware Group
A former Envoy Air Inc. employee has filed a class-action lawsuit against the regional airline and Oracle Corp., alleging negligence in protecting sensitive employee data exposed during a July 2025 cyberattack. The breach, attributed to the CL0P ransomware group, compromised personal information stored in Oracle’s business-software system, including Social Security numbers, birth dates, and financial account details.
Khianna Parks, the plaintiff, seeks to represent current and former Envoy Air employees affected by the incident. The complaint was filed on Wednesday in the U.S. District Court for the Western District of Texas. Envoy Air, a subsidiary of American Airlines Group Inc., has not yet publicly responded to the allegations.
The lawsuit highlights growing concerns over third-party vendor security risks and the persistent threat posed by ransomware groups targeting enterprise software systems. The breach underscores the potential long-term consequences of exposed personal data, including identity theft and financial fraud.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2025
669
Ransomware
16 Jun 2025 • Envoy Air
Envoy Air (MQ)
Envoy Air Oracle E-Business Suite Data Breach Linked to Clop Ransomware
514
MEDIUM-155
ENV1802118101925
Envoy Air, a regional subsidiary of American Airlines, confirmed a cybersecurity breach linked to the Clop ransomware group, which exploited a zero-day vulnerability (CVE-2025-61882) in its Oracle E-Business Suite. The attack was part of a broader global campaign targeting multiple organizations. While the breach exposed business and commercial contact data, Envoy Air clarified that no sensitive customer or financial information was compromised. The Clop group leaked stolen data on its dark web platform, accusing the airline of neglecting cybersecurity. The incident follows a pattern of Clop’s large-scale data exfiltration operations, leveraging unpatched vulnerabilities in enterprise systems. Envoy Air engaged law enforcement and initiated an investigation, but the breach underscores ongoing risks in third-party enterprise applications, particularly in the aviation sector. The attack did not disrupt operations but raised concerns about supply-chain vulnerabilities and the exposure of non-sensitive corporate data to malicious actors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2025
767
Ransomware
01 May 2025 • Envoy Air
Envoy Air
Cyberattack on Envoy Air via Oracle E-Business Suite Vulnerability
666
HIGH-101
ENV1533115102225
Envoy Air, a subsidiary of American Airlines, fell victim to a cyberattack executed by the Cl0p ransomware group, exploiting a vulnerability in Oracle E-Business Suite applications. While the company confirmed that no sensitive or customer data was compromised, a limited amount of business information and commercial contact details may have been exposed. The attack was part of a broader campaign targeting Oracle’s widely used enterprise software, affecting multiple organizations globally. Envoy Air is actively investigating the incident in coordination with law enforcement. Experts warn that the exploitation window—spanning nearly three months (July to October 2025)—allowed threat actors to exfiltrate large volumes of data from unpatched systems. The attack underscores risks tied to third-party dependencies, operational disruptions, and potential long-term erosion of public trust. Google’s threat intelligence suggests over 100 organizations could be impacted, with many possibly unaware of their compromise during the zero-day period. Patches for the vulnerabilities (CVE-2025-61882, CVE-2025-61884) were released in October 2025, but delayed mitigation may have exacerbated exposure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Envoy Air ??
What was Envoy Air's A.I Rankiteo Cyber Score in May 2026 ??
What was Envoy Air's A.I Rankiteo Cyber Score in April 2026 ??
What was Envoy Air's A.I Rankiteo Cyber Score in March 2026 ??
What was Envoy Air's A.I Rankiteo Cyber Score in February 2026 ??
What was Envoy Air's A.I Rankiteo Cyber Score in January 2026 ??
What was Envoy Air's A.I Rankiteo Cyber Score in December 2025 ??
What was Envoy Air's A.I Rankiteo Cyber Score in November 2025 ??
What was Envoy Air's A.I Rankiteo Cyber Score in October 2025 ??
What was Envoy Air's A.I Rankiteo Cyber Score in September 2025 ??
What was Envoy Air's A.I Rankiteo Cyber Score in August 2025 ??
What was Envoy Air's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Envoy Air's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Envoy Air ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Envoy Air's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?