Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Iberia

Iberia Vendor Cyber Rating & Cyber Score

iberia.com

Iberia is Spain’s number-one airline group and the leader in the Europe-Latin America market, with the single greatest array of destinations and flight frequencies. Together with British Airways, we’re part of the IAG Group, with the third-highest receipts in Europe and sixth worldwide.. Iberia is also a founding member of the Oneworld Alliance, which offers passengers the best connections to around 700 destinations worldwide.


Iberia A.I CyberSecurity Scoring

Iberia
Company Information
Website:http://www.iberia.com
Employees number:10,823
Number of followers:418,965
NAICS:481
Industry Type:Airlines and Aviation
Homepage:iberia.com
Iberia Risk Score (AI oriented)
Between 0 and 549
logo
IberiaAirlines and Aviation
Updated:
29/03/2026
414/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Iberia Global Score (TPRM)
xxxx
logo
IberiaAirlines and Aviation
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Iberia
IberiaCritical
Current Score
414C (CRITICAL)
01000
4 incidents
-151 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
440Before Incident
MAY 2026
425Before Incident
APRIL 2026
424Before Incident
MARCH 2026
409Before Incident
FEBRUARY 2026
678Before Incident
Ransomware
08 Feb 2026Iberia
Iberia: Air Côte d'Ivoire confirms cyberattack following ransomware claims

Cyberattack Disrupts Air Côte d’Ivoire, INC Ransomware Gang Claims Data Theft

398After Incident
CRITICAL-280
IBE1771962749
Cyberattack Disrupts Air Côte d’Ivoire, INC Ransomware Gang Claims Data Theft Air Côte d’Ivoire, the flagship airline of Côte d’Ivoire, confirmed a cyberattack on February 8 that disrupted parts of its information systems, forcing the company to activate business continuity measures. The INC ransomware gang later claimed responsibility, alleging it stole 208 GB of data and demanding an undisclosed ransom by February 24. In a statement released on February 16, the airline acknowledged the breach and reported that technical teams were deployed to maintain flight operations. While assuring passengers that its flight program remained stable under international safety standards, Air Côte d’Ivoire warned of potential risks to service providers, employees, and travelers due to the data leak. The airline notified France’s ANSSI and Côte d’Ivoire’s ARTCI, while the country’s Computer Emergency Response Team (CI-CERT) and international experts launched an investigation into the incident. Based in Abidjan, Air Côte d’Ivoire operates a fleet of 14 aircraft, serving destinations across Africa, Lebanon, and France. The INC ransomware group, known for high-profile attacks including breaches of the Pennsylvania Attorney General’s Office, the governments of Panama (2025) and Hungary (2024), and a U.S. emergency alert system disruption in November has increasingly targeted regional airlines. Last year, similar attacks affected South African Airways, Hawaiian Airlines, Qantas, Iberia, and multiple Russian carriers, highlighting the aviation sector’s vulnerability to ransomware threats.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 208 GBSystems Affected: Information systemsOperational Impact: Disruption of operations, activation of business continuity measuresBrand Reputation Impact: Potential risks to service providers, employees, and travelers due to data leakIdentity Theft Risk: Potential risk to travelers and employees
DATA BREACH
Sensitivity Of Data: Potentially sensitive data of service providers, employees, and travelersData Exfiltration: 208 GB of data allegedly stolenPersonally Identifiable Information: Potential PII of travelers and employees
JANUARY 2026
617Before Incident
Breach
07 Jan 2026Iberia
Iberia: Spanish airline Iberia attributes recent data breach claims to November incident

Iberia Data Breach via Infostealer Malware

562After Incident
CRITICAL-55
IBE1767821517
Iberia Confirms Data Breach Exposing Aircraft Technical Data and Customer Information Spanish airline Iberia has acknowledged a data breach involving 77 GB of sensitive internal documents and customer data, first identified in November 2024. The breach was exposed this week by cybersecurity firm Hudson Rock, which linked the incident to a threat actor known as Zestix, who had been auctioning stolen corporate data from approximately 50 companies and law firms. The attacker allegedly compromised Iberia’s ShareFile instance—a file-sharing platform developed by Progress Software—after infecting an employee’s device with infostealer malware to harvest credentials. The stolen data includes technical materials for Airbus A320 and A321 aircraft, such as maintenance files, engine specifications, damage charts, and confidential fleet information. While Iberia stated that the exposed data was "non-operational" and did not compromise flight safety, Hudson Rock noted that the files contained digital signatures and proprietary configurations that could be valuable to competitors or state actors. In addition to technical documents, the breach exposed personal data of Iberia customers, including names, email addresses, phone numbers, Iberia Club membership numbers, and booking reference codes for future flights. Iberia reported the incident to Spanish regulators, including the Spanish Data Protection Agency, and notified affected customers in late 2024. The airline also implemented two-factor authentication (2FA) for impacted accounts to prevent unauthorized access. Zestix, the threat actor behind the breach, operates as an initial access broker within Russian-language cybercrime forums, selling compromised corporate access for Bitcoin. Hudson Rock’s investigation linked one of Zestix’s aliases to an Iranian national and associated the group with the Funksec cybercriminal collective. While Iberia confirmed the breach, none of the other companies listed in Hudson Rock’s report have publicly acknowledged being affected.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (ransom demand), Data exfiltration for sale
IMPACT
Data Compromised: 77 GB of dataSystems Affected: ShareFile (Progress Software)Operational Impact: Limited, non-operational data exposed; flight safety not compromisedBrand Reputation Impact: Potential impact due to exposure of proprietary data and customer informationLegal Liabilities: Reported to Spanish Data Protection AgencyIdentity Theft Risk: High (customer personal data exposed)
DATA BREACH
Technical materials for A320 and A321 aircraftMaintenance filesEngine dataAircraft damage chartsConfidential fleet dataCustomer personal dataSensitivity Of Data: High (proprietary aircraft data, customer PII)NamesEmail addressesPhone numbersIberia Club membership numbersBooking reference codes
DECEMBER 2025
730Before Incident
Ransomware
01 Dec 2025Iberia
Iberia Airlines and Third-party vendor: Iberia Airlines in Spain Hit by Major Cyberattack as Passenger Data Theft Sparks Tourism Security Concerns Across Europe

Iberia Airlines Hit by Major Cyberattack as Everest Ransomware Group Steals Passenger Data

612After Incident
CRITICAL-118
THIIBE1774081558
Iberia Airlines Hit by Major Cyberattack as Everest Ransomware Group Steals Passenger Data Iberia Airlines, one of Spain’s leading carriers, has suffered a significant cyberattack resulting in the theft of sensitive passenger data. The breach, attributed to the Everest ransomware group, exposed approximately 596 GB of information, including frequent flyer records, personal details, and travel booking data. While full payment card details remained secure, attackers claimed to have accessed partially masked credit card information, raising concerns over potential phishing and fraud risks. The incident occurred after unauthorized access was gained through a third-party vendor, highlighting vulnerabilities in aviation’s interconnected digital infrastructure. The Everest group demanded a $6 million ransom, threatening to release or sell the stolen data if unpaid a move that could fuel large-scale fraud and reputational damage for Iberia and Spain’s tourism sector. Affected passengers, particularly Iberia Club members, were notified of the breach, with the airline confirming no immediate fraudulent activity had been detected. However, travelers were advised to remain vigilant against phishing attempts, as stolen data including names, emails, and travel histories could be exploited for targeted scams. This attack follows a pattern of high-profile cyber incidents in Europe’s aviation sector, including Everest’s previous disruption of the MUSE check-in platform in September 2025, which caused delays at major airports like London Heathrow and Berlin Brandenburg. The breach underscores the growing cybersecurity risks facing airlines, airports, and tourism-dependent economies, as digital transformation increases reliance on vulnerable third-party systems. With Spain’s tourism industry heavily dependent on secure digital operations, the incident has reignited calls for stronger cybersecurity measures across Europe’s aviation and travel sectors. The breach serves as a stark reminder of the evolving threats to passenger data and the operational integrity of global air transport networks.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 596 GB of sensitive passenger dataOperational Impact: Potential phishing and fraud risks; reputational damage to Iberia and Spain’s tourism sectorBrand Reputation Impact: Reputational damage for Iberia and Spain’s tourism sectorIdentity Theft Risk: High (stolen personal details, travel histories, and partially masked credit card information)Payment Information Risk: Partially masked credit card information accessed
DATA BREACH
Frequent flyer recordsPersonal detailsTravel booking dataPartially masked credit card informationSensitivity Of Data: HighData Exfiltration: Yes (596 GB stolen)Personally Identifiable Information: Names, emails, travel histories
NOVEMBER 2025
730Before Incident
OCTOBER 2025
729Before Incident
SEPTEMBER 2025
728Before Incident
AUGUST 2025
727Before Incident
JULY 2025
726Before Incident
JUNE 2023
781Before Incident
Ransomware
16 Jun 2023Iberia
McDonald’s India, Iberia Airlines, Nissan and Under Armour: Everest Ransomware Claims McDonalds India Breach Involving Customer Data

Everest Ransomware Group Claims Breach of McDonald’s India

688After Incident
CRITICAL-93
MCDIBENISDEC1768955534
Everest Ransomware Group Claims Breach of McDonald’s India, Allegedly Stealing 861GB of Sensitive Data The Everest ransomware group has claimed responsibility for a breach of McDonald’s India, the fast-food giant’s Indian subsidiary, allegedly exfiltrating 861 GB of customer data and internal documents. The claim, posted on the group’s dark web leak site on January 20, 2026, includes screenshots purportedly showing financial reports (2023–2026), audit trails, ERP migration files, pricing data, and confidential internal communications. Among the leaked materials are structured directories with month-by-month accounting records, a folder labeled "Investor Info" containing board-level documents, and a "Contact Database" with details of investors and business partners including names, addresses, phone numbers, and emails across the US, UK, Singapore, and India. Additional screenshots reveal store-level data, such as manager names, company email addresses (under mcdonaldsindia.com), and direct contact numbers for multiple outlet locations. Everest has set a two-day deadline for McDonald’s India to respond, though the company has yet to issue an official statement. The claims remain unverified pending confirmation from McDonald’s or further evidence. The group, one of the most active ransomware operators in 2025, has maintained its aggressive campaign into 2026, targeting high-profile organizations including Nissan, ASUS, Chrysler, Iberia Airlines, Under Armour, Petrobras, AT&T, and Dublin Airport. Investigations into the alleged McDonald’s India breach are ongoing.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransom demand)
IMPACT
Data Compromised: 861 GBBrand Reputation Impact: High (alleged breach of a global brand)Identity Theft Risk: High (PII exposed)
DATA BREACH
Financial reportsAudit trailsERP migration filesPricing dataInternal communicationsInvestor informationStore-level dataContact databasesSensitivity Of Data: High (confidential business and personal data)Data Exfiltration: Yes (861 GB allegedly stolen)NamesAddressesPhone numbersEmail addressesManager details

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Iberia ?
?
What was Iberia's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Iberia's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Iberia's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Iberia's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Iberia's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Iberia's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Iberia's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Iberia's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Iberia's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Iberia's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Iberia's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Iberia's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Iberia ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Iberia's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?