ShinyHunters Strikes Air France & KLM with Data Breach

Ransomware

Summary

On October 3, 2025, the notorious ransomware group ShinyHunters claimed responsibility for a data breach targeting Air France & KLM (airfranceklm.com), a major airline operating in France and the Netherlands. The attackers have threatened to release sensitive data unless their demands are met.


Incident Report

FieldDetails
TargetAir France & KLM
Domainairfranceklm.com
CountryFrance
Attacking GroupShinyHunters
Date ReportedOctober 3, 2025
Threat Actor Statement“The full leak will be published soon, unless a company representative contacts us via the channels provided.”

Air France & KLM is an international airline partnership under the parent company Air France-KLM Group. Based respectively in France and the Netherlands, the airlines provide passenger and cargo services globally. Offering premium and economy services, they operate in major domestic and international routes. The brands stand for comfort, reliability, and customer service. The loyalty programme ‘Flying Blue’ rewards frequent flyers.

ShinyHunters is a well-known cybercriminal group responsible for various high-profile data breaches. They often target large corporations and demand ransom for not releasing stolen data.

To proactively respond to such threats, it’s crucial to monitor the dark web for potential data breaches and compromised information. Utilizing tools like the email breach checker at MSP Dark Intel can help organizations keep an eye on their domains and protect against data leaks.

Recommendations

  • Monitor your domains and email addresses for exposure using reputable threat intelligence tools.
  • Conduct a full compromise assessment and incident response drill internally.
  • Verify backups and ensure they are offline and ransomware-resistant.
  • Educate staff on phishing, social engineering, and lateral movement techniques used by groups like Qilin.
  • Engage with cyber forensics and legal counsel before initiating contact with threat actors.

Check Your Exposure

Wondering if your organization or employees are impacted by recent breach activity?


Disclaimer

The MSPDarkIntel team does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information.
All breach data reported here is sourced from publicly available threat intelligence feeds for awareness and early-warning purposes only.
Our goal is to inform organizations of emerging threats so they can take timely defensive action.

Keep reading