2025 Iberia — supplier hack exposes customer names, emails, Iberia Club numbers
Data compromised
Customer names, email addresses, and Iberia Club frequent-flyer numbers; passwords and full card data not involved per airline
Technical writeup
Spanish flag carrier Iberia emailed customers in November 2025 that personal information was compromised after unauthorized access to systems belonging to one of its suppliers. The airline stated names, email addresses, and Iberia Club frequent-flyer numbers were exposed while passwords and full payment-card data were not involved. Iberia required verification codes to change account email addresses and notified law enforcement; it did not name the supplier or publish a victim count. SecurityWeek noted the notifications followed forum claims of roughly 77 GB of airline data but Iberia did not link the supplier incident to those claims.
Root cause
Unauthorized access to systems of an Iberia third-party supplier