HomeLatest NewsCyber SecurityAir France, KLM confirm data breach exposing customer names and Flying Blue details

Air France, KLM confirm data breach exposing customer names and Flying Blue details

Following unauthorised access at a third-party customer service platform, Air France and KLM inform customers that their names and Flying Blue loyalty details may have been exposed in the data breach.

Preferred Source of Google

Dutch flag carrier KLM and sister airline Air France have reported a involving unauthorised access to a third‑party customer service platform. The breach, which took place in late July 2025, is believed to have impacted personal data of passengers including names, contact details, loyalty credentials and email subject lines, though more sensitive information such as passwords, passport numbers or credit card details was not compromised. The airlines say their internal systems remain secure and unaffected by the incident.

The breach is believed to have originated from vulnerabilities within a third-party platform used by multiple airlines to manage customer service interactions. While the specific vendor involved in the Air France-KLM incident has not been officially named, the affected system is reportedly part of a widely adopted cloud-based environment commonly used for customer engagement and contact centre operations.

Publicly available details indicate that KLM has worked with for its Service Cloud platform. These platforms support the airline’s customer service operations, including managing passenger enquiries, booking records and Flying Blue loyalty programme interactions. However, KLM has not confirmed whether either provider was involved in this incident, citing the ongoing investigation.

Advertisement
Saksham Bharat 2026
Saksham Bharat 2026
A multi-stakeholder dialogue on skilling gap in Cybersecurity, Data Resilience and AI — and the roadmap to a Saksham Bharat.
Register Now →
VeeamON 2026 Tour India - Mumbai
VeeamON 2026 Tour India - Mumbai
A VeeamON 2026 India Leadership Series Mumbai for senior public sector and government technology leaders.
Register Now →
Cyber Surakshit Uttar Pradesh
Cyber Surakshit Uttar Pradesh
Find out strategies, frameworks and solutions for building a resilient and secure digital ecosystem across Uttar Pradesh.
Register Now →
VeeamON 2026 Tour India - Bengaluru
VeeamON 2026 Tour India - Bengaluru
A VeeamON 2026 India Leadership Series Bengaluru for senior public sector and government technology leaders.
Register Now →
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

What was accessed and who is affected

According to KLM, the data exposure affects only passengers who had previously interacted with their customer service via the platform in question; the breach occurred within a third‑party system used across the Air France–KLM group. Specifically, compromised details include first and last names, contact information, Flying Blue membership numbers and tier status, and subject lines from customer service emails. Although full numbers of affected individuals have not been disclosed, industry sources indicate the breach could involve a significant number of users, potentially running into hundreds of thousands across multiple jurisdictions.

With a global footprint spanning 90 countries and nearly 300 destinations, the Air France-KLM Group operates a fleet of 564 aircraft and employs approximately 78,000 people. In 2024, the group carried 98 million passengers worldwide.

While financial and travel booking data were not exposed, cybersecurity experts caution that the breached information could still be leveraged for targeted phishing campaigns, especially when combined with public social media or travel data. Affected users may receive messages appearing credible due to the presence of their frequent flyer status or customer support history.

Advertisement

Airline response and regulatory notification

KLM has stated that internal IT security teams, in conjunction with the external vendor, promptly executed containment measures and additional protections to prevent recurrence. As part of its compliance obligations under the General Data Protection Regulation (GDPR), the airline reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) while Air France notified its French counterpart CNIL (Commission Nationale de l’Informatique et des Libertés).

The airlines also initiated direct communication with affected customers, sending individual email alerts with details of the breach and guidance on digital hygiene. To help affected customers guard against phishing, both airlines have issued advisories to discard unsolicited communications that request personal details or urge immediate action. They recommended that users verify authenticity before responding.

Aviation industry cyber‑risk implications

This breach is the latest in a series of aviation data incidents that exploit vendor vulnerabilities. In June, Qantas reported a similar third‑party breach affecting approximately 6 million passengers. In 2021, a major incident involving global aviation IT firm SITA compromised passenger data across multiple Star Alliance airlines, including Singapore Airlines and Lufthansa.

Advertisement

The recurring risk highlights a systemic weakness in outsourcing customer interaction platforms. As airlines increasingly digitise their operations, the cybersecurity posture of third-party providers becomes central to trust and continuity. Cybersecurity firms have also flagged that criminal groups, including the ‘Scattered Spider’ collective, are increasingly targeting airline systems through social engineering attacks on service providers.

According to multiple reports, this incident may form part of a wave of supply‑chain attacks targeting Salesforce platforms, with groups such as ShinyHunters reportedly active in these campaigns. The shared infrastructure used by many large travel firms makes these platforms high-value targets for attackers seeking broad access through a single point of failure.

“While KLM’s swift response and transparency may help soothe customer concerns, the broader aviation sector must treat vendor cybersecurity as an essential component of operational integrity,” said Golok Kumar Simli, former Principal Advisor and Chief Technology Officer, Affairs, Government of India.

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Mohd Ujaley
Mohd Ujaley
Mohd Ujaley is a journalist specialising in the intersection of technology with government, public sector, defence and large enterprises. As Editorial Director at Tech Observer Magazine, he leads editorial strategy, moderates industry discussions and engages with key stakeholders to shape conversations around technology, policy and digital transformation. With over 15 years of experience, Ujaley has held editorial roles at prestigious publications including The Economic Times, ETGovernment, Indian Express Group, Financial Express, Express Computer and CRN India. He holds a Bachelor’s degree in Business Economics, a Master’s in Mass Communication from Guru Gobind Singh Indraprastha University (GGSIPU), a Parliamentary Fellowship from The Institute of Constitutional and Parliamentary Studies and a Certificate in Public Policy from St. Stephen’s College, Delhi.
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

India to Lead Global IT Security Standards Body for Two Years

India will chair the Common Criteria Development Board from April 2026, gaining influence over international IT security certification standards recognised by 38 countries.

RELATED ARTICLES