Iberia A.I CyberSecurity Scoring
Iberia
Company Information
Website:http://www.iberia.com
Employees number:10,823
Number of followers:418,965
NAICS:481
Industry Type:Airlines and Aviation
Homepage:iberia.com
Iberia Risk Score (AI oriented)
Between 0 and 549
IberiaAirlines and Aviation
Updated:
29/03/2026
29/03/2026
414/1000
Critical
C
Iberia Global Score (TPRM)
xxxx
IberiaAirlines and Aviation
Score locked

IberiaCritical
Current Score
414C (CRITICAL)
01000
4 incidents
-151 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
440
MAY 2026
425
APRIL 2026
424
MARCH 2026
409
FEBRUARY 2026
678
Ransomware
08 Feb 2026 • Iberia
Iberia: Air Côte d'Ivoire confirms cyberattack following ransomware claims
Cyberattack Disrupts Air Côte d’Ivoire, INC Ransomware Gang Claims Data Theft
398
CRITICAL-280
IBE1771962749
Cyberattack Disrupts Air Côte d’Ivoire, INC Ransomware Gang Claims Data Theft
Air Côte d’Ivoire, the flagship airline of Côte d’Ivoire, confirmed a cyberattack on February 8 that disrupted parts of its information systems, forcing the company to activate business continuity measures. The INC ransomware gang later claimed responsibility, alleging it stole 208 GB of data and demanding an undisclosed ransom by February 24.
In a statement released on February 16, the airline acknowledged the breach and reported that technical teams were deployed to maintain flight operations. While assuring passengers that its flight program remained stable under international safety standards, Air Côte d’Ivoire warned of potential risks to service providers, employees, and travelers due to the data leak. The airline notified France’s ANSSI and Côte d’Ivoire’s ARTCI, while the country’s Computer Emergency Response Team (CI-CERT) and international experts launched an investigation into the incident.
Based in Abidjan, Air Côte d’Ivoire operates a fleet of 14 aircraft, serving destinations across Africa, Lebanon, and France. The INC ransomware group, known for high-profile attacks including breaches of the Pennsylvania Attorney General’s Office, the governments of Panama (2025) and Hungary (2024), and a U.S. emergency alert system disruption in November has increasingly targeted regional airlines. Last year, similar attacks affected South African Airways, Hawaiian Airlines, Qantas, Iberia, and multiple Russian carriers, highlighting the aviation sector’s vulnerability to ransomware threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
617
Breach
07 Jan 2026 • Iberia
Iberia: Spanish airline Iberia attributes recent data breach claims to November incident
Iberia Data Breach via Infostealer Malware
562
CRITICAL-55
IBE1767821517
Iberia Confirms Data Breach Exposing Aircraft Technical Data and Customer Information
Spanish airline Iberia has acknowledged a data breach involving 77 GB of sensitive internal documents and customer data, first identified in November 2024. The breach was exposed this week by cybersecurity firm Hudson Rock, which linked the incident to a threat actor known as Zestix, who had been auctioning stolen corporate data from approximately 50 companies and law firms.
The attacker allegedly compromised Iberia’s ShareFile instance—a file-sharing platform developed by Progress Software—after infecting an employee’s device with infostealer malware to harvest credentials. The stolen data includes technical materials for Airbus A320 and A321 aircraft, such as maintenance files, engine specifications, damage charts, and confidential fleet information. While Iberia stated that the exposed data was "non-operational" and did not compromise flight safety, Hudson Rock noted that the files contained digital signatures and proprietary configurations that could be valuable to competitors or state actors.
In addition to technical documents, the breach exposed personal data of Iberia customers, including names, email addresses, phone numbers, Iberia Club membership numbers, and booking reference codes for future flights. Iberia reported the incident to Spanish regulators, including the Spanish Data Protection Agency, and notified affected customers in late 2024. The airline also implemented two-factor authentication (2FA) for impacted accounts to prevent unauthorized access.
Zestix, the threat actor behind the breach, operates as an initial access broker within Russian-language cybercrime forums, selling compromised corporate access for Bitcoin. Hudson Rock’s investigation linked one of Zestix’s aliases to an Iranian national and associated the group with the Funksec cybercriminal collective. While Iberia confirmed the breach, none of the other companies listed in Hudson Rock’s report have publicly acknowledged being affected.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
730
Ransomware
01 Dec 2025 • Iberia
Iberia Airlines and Third-party vendor: Iberia Airlines in Spain Hit by Major Cyberattack as Passenger Data Theft Sparks Tourism Security Concerns Across Europe
Iberia Airlines Hit by Major Cyberattack as Everest Ransomware Group Steals Passenger Data
612
CRITICAL-118
THIIBE1774081558
Iberia Airlines Hit by Major Cyberattack as Everest Ransomware Group Steals Passenger Data
Iberia Airlines, one of Spain’s leading carriers, has suffered a significant cyberattack resulting in the theft of sensitive passenger data. The breach, attributed to the Everest ransomware group, exposed approximately 596 GB of information, including frequent flyer records, personal details, and travel booking data. While full payment card details remained secure, attackers claimed to have accessed partially masked credit card information, raising concerns over potential phishing and fraud risks.
The incident occurred after unauthorized access was gained through a third-party vendor, highlighting vulnerabilities in aviation’s interconnected digital infrastructure. The Everest group demanded a $6 million ransom, threatening to release or sell the stolen data if unpaid a move that could fuel large-scale fraud and reputational damage for Iberia and Spain’s tourism sector.
Affected passengers, particularly Iberia Club members, were notified of the breach, with the airline confirming no immediate fraudulent activity had been detected. However, travelers were advised to remain vigilant against phishing attempts, as stolen data including names, emails, and travel histories could be exploited for targeted scams.
This attack follows a pattern of high-profile cyber incidents in Europe’s aviation sector, including Everest’s previous disruption of the MUSE check-in platform in September 2025, which caused delays at major airports like London Heathrow and Berlin Brandenburg. The breach underscores the growing cybersecurity risks facing airlines, airports, and tourism-dependent economies, as digital transformation increases reliance on vulnerable third-party systems.
With Spain’s tourism industry heavily dependent on secure digital operations, the incident has reignited calls for stronger cybersecurity measures across Europe’s aviation and travel sectors. The breach serves as a stark reminder of the evolving threats to passenger data and the operational integrity of global air transport networks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
730
OCTOBER 2025
729
SEPTEMBER 2025
728
AUGUST 2025
727
JULY 2025
726
JUNE 2023
781
Ransomware
16 Jun 2023 • Iberia
McDonald’s India, Iberia Airlines, Nissan and Under Armour: Everest Ransomware Claims McDonalds India Breach Involving Customer Data
Everest Ransomware Group Claims Breach of McDonald’s India
688
CRITICAL-93
MCDIBENISDEC1768955534
Everest Ransomware Group Claims Breach of McDonald’s India, Allegedly Stealing 861GB of Sensitive Data
The Everest ransomware group has claimed responsibility for a breach of McDonald’s India, the fast-food giant’s Indian subsidiary, allegedly exfiltrating 861 GB of customer data and internal documents. The claim, posted on the group’s dark web leak site on January 20, 2026, includes screenshots purportedly showing financial reports (2023–2026), audit trails, ERP migration files, pricing data, and confidential internal communications.
Among the leaked materials are structured directories with month-by-month accounting records, a folder labeled "Investor Info" containing board-level documents, and a "Contact Database" with details of investors and business partners including names, addresses, phone numbers, and emails across the US, UK, Singapore, and India. Additional screenshots reveal store-level data, such as manager names, company email addresses (under mcdonaldsindia.com), and direct contact numbers for multiple outlet locations.
Everest has set a two-day deadline for McDonald’s India to respond, though the company has yet to issue an official statement. The claims remain unverified pending confirmation from McDonald’s or further evidence.
The group, one of the most active ransomware operators in 2025, has maintained its aggressive campaign into 2026, targeting high-profile organizations including Nissan, ASUS, Chrysler, Iberia Airlines, Under Armour, Petrobras, AT&T, and Dublin Airport. Investigations into the alleged McDonald’s India breach are ongoing.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Iberia ??
What was Iberia's A.I Rankiteo Cyber Score in May 2026 ??
What was Iberia's A.I Rankiteo Cyber Score in April 2026 ??
What was Iberia's A.I Rankiteo Cyber Score in March 2026 ??
What was Iberia's A.I Rankiteo Cyber Score in February 2026 ??
What was Iberia's A.I Rankiteo Cyber Score in January 2026 ??
What was Iberia's A.I Rankiteo Cyber Score in December 2025 ??
What was Iberia's A.I Rankiteo Cyber Score in November 2025 ??
What was Iberia's A.I Rankiteo Cyber Score in October 2025 ??
What was Iberia's A.I Rankiteo Cyber Score in September 2025 ??
What was Iberia's A.I Rankiteo Cyber Score in August 2025 ??
What was Iberia's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Iberia's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Iberia ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Iberia's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?