← Iberia

2025 Iberia — supplier hack exposes customer names, emails, Iberia Club numbers

2025 Unknown records affected Share on X

Data compromised

Customer names, email addresses, and Iberia Club frequent-flyer numbers; passwords and full card data not involved per airline

Technical writeup

Spanish flag carrier Iberia emailed customers in November 2025 that personal information was compromised after unauthorized access to systems belonging to one of its suppliers. The airline stated names, email addresses, and Iberia Club frequent-flyer numbers were exposed while passwords and full payment-card data were not involved. Iberia required verification codes to change account email addresses and notified law enforcement; it did not name the supplier or publish a victim count. SecurityWeek noted the notifications followed forum claims of roughly 77 GB of airline data but Iberia did not link the supplier incident to those claims.

Root cause

Unauthorized access to systems of an Iberia third-party supplier

References