Listen to this Post

A cyber‑extortion group calling itself the Everest ransomware group claims to have hacked two major companies — Iberia Airlines (Spain’s flag carrier) and Money Mart (a North American financial‑services firm) — threatening to publish massive caches of stolen data. According to the group, the haul includes 596 GB of passenger databases from Iberia, and roughly 80,000 internal financial documents from Money Mart — files containing social security numbers, driver’s licences, credit‑card information and other sensitive personal data.
Hackread
+1
the Incident
The ransomware group says it infiltrated Iberia Airlines and exfiltrated a 596 GB database — including booking records, identity information, travel history, payment records, and even internal communications related to bookings. The stolen data reportedly affects millions of customers across Spain, Latin America, and other regions where Iberia operates. The group claims it had sustained access, which allowed them to read or alter bookings, passenger contact info, seat assignments, meals, and even cancel tickets.
Hackread
At the same time, the group also targeted Money Mart, claiming to have stolen over 80,000 internal files. The exposed data allegedly includes customers’ financial information, credit‑card data, transaction history, identity documents (such as SSNs and driver’s licences), plus personal details and employment history of customers and employees. The group reportedly issued a deadline for ransom — threatening to publish all data publicly if demands are not met.
Cybernews
These events are part of a wider surge in data‑extortion operations by Everest: the gang has reportedly claimed more than 250 victims since 2023, spanning airlines, financial services, retail loyalty programs, and other industries.
Cybernews
+2
The Realist Juggernaut
+2
For its part, Iberia confirmed a breach — but claims the intrusion was via a third‑party supplier, not its own core systems. The airline says customer credentials, payment details and passwords were not compromised; likely exposed data includes names, email addresses and loyalty‑account identifiers.
Cybernews
+2
Infosecurity Magazine
+2
Still, a separate claim on the dark‑web “leak site” offered 77 GB of internal documentation — including sensitive aircraft maintenance and technical files. It remains unclear whether this release is connected to the same breach Iberia notified customers about.
CyberInsider
+2
blog.rankiteo.com
+2
What’s Really at Stake
The scale and nature of the data claimed stolen by Everest are deeply worrying. Here’s what’s concerning — and why it should matter to every regular traveler or customer:
Massive privacy risk: If true, the Iberia leak could expose millions of travellers’ identities, travel histories, payment metadata, and contact info. That gives attackers enough fuel for identity theft, credit‑card fraud, phishing campaigns, and even targeted social engineering attacks.
Operational & ticketing manipulation: The ability to read or alter bookings — seat assignments, meal preferences, passenger contact info — could allow attackers to hijack tickets, reroute journeys, or impersonate travellers. The threat isn’t purely financial; it’s about control over people’s travel.
Corporate and supply‑chain vulnerability: The alleged leak of aircraft maintenance and internal technical documents (from the 77 GB offer) raises the spectre of industrial espionage — or even sabotage. If sensitive engineering data is exposed, it can compromise safety, regulatory compliance, or competitive advantage.
Systemic threat to financial services: With firms like Money Mart targeted, the breach underlines how financial‑service providers — especially those handling loans, check‑cashing, prepaid cards, or credit services — are gifted targets for ransomware gangs. Personal and financial data from both customers and employees can be used for long‑term identity fraud.
Double‑extortion business model: Unlike simple ransomware encryption, the attackers appear to exfiltrate data first — then threaten release if ransom demands aren’t met. This means even paying the ransom might not prevent eventual leaks.
In short: whether you fly occasionally or use financial‑service providers, these hacks show how deeply cyber‑threats are now embedded in everyday services.
What Undercode Say:
Everest’s claimed attacks mark a turning point — not just for aviation or financial firms, but for how ransomware is evolving globally. Gone are the days when attackers simply locked files and demanded payment in exchange for decryption keys. Today’s players increasingly focus on massive data scraping, targeting third‑party vendors and supply chains, and generating leverage through highly sensitive, high‑volume leaks. If their claims hold up — and recent history suggests they often do — we are witnessing a shift from technical sabotage to mass‑scale data exploitation and extortion.
Why is this happening now? Several factors converge:
Brittle vendor ecosystems: Airlines and financial firms rely heavily on third-party suppliers — for customer relations, payment processing, maintenance, data storage. That increases the attack surface dramatically. A vulnerability at a supplier can compromise an entire airline or bank — without touching its primary security perimeter.
Monetizable data everywhere: Travel history, loyalty programs, payment patterns, financial services data — all are gold mines for identity thieves, credit‑card fraudsters, and resale markets on the dark web. Attackers realise that data from “non‑traditional” sources (e.g., loyalty programs, check‑cashing firms) can yield high returns.
Shift to data‑first extortion: Encryption ransoms are risky — victims may restore from backups. But data leaks are sticky: once exposed, they’re nearly impossible to fully retract. That gives attackers greater leverage and a compelling model: not just money, but fear, reputational damage and regulatory liability.
Chained risk across industries: Airlines, financial firms, retailers, loyalty‑program operators — all form a web of interconnected services. A breach in one link can ripple across many sectors. Attackers exploit this interconnection for maximum disruption.
This trend also exposes deeper societal risks: mass leaks erode trust in institutions, shake consumer confidence, and force firms to rebuild from reputational rubble — if they survive. Regulators and security professionals must accept that breaches are no longer isolated incidents. Instead, they are systemic threats — affecting identity, commerce, mobility, and trust.
Going forward, companies must assume that if they store or process personal data — or rely on third parties — they are already under threat. Effective cybersecurity must involve not just hardened firewalls, but vendor vetting, supply‑chain audits, data minimization, strict access controls, and breach‑response communication protocols.
For travellers, customers and employees: vigilance matters. Watch out for unusual emails, phishing attempts, unauthorized account activities — don’t wait for the leak to become public before acting.
Fact Checker Results:
✅ The claim that Everest targeted Iberia Airlines and stole 596 GB has been reported by multiple independent cybersecurity outlets.
Hackread
+1
✅ Money Mart is confirmed as another victim of Everest, with 80,000+ internal files allegedly stolen, including sensitive customer data.
Cybernews
❗ Iberia’s official statement says the breach came via a third‑party supplier and that no passwords or payment credentials were affected — meaning some of Everest’s more extreme claims (like full payment data theft) remain unverified.
Infosecurity Magazine
+1
Prediction:
Expect a new wave of pressure on service providers — not just airlines — in sectors like travel, finance and retail. As threat actors continue to exploit supply chains and third‑party dependencies, we’ll likely see:
More double‑extortion attacks, where data leaks accompany or replace encryption‑based ransomware.
Increasing demand from regulators for transparency and accountability — airlines and lenders may be forced to publicly disclose breaches and the full scope of affected data.
A surge in identity theft and phishing attacks, targeting customers whose personal data has been exposed — especially credit‑card holders, frequent travellers, and loyalty‑program users.
Companies scrambling to adopt zero‑trust supply‑chain frameworks, with stricter audits, access controls, and contractual liability clauses for third‑party vendors.
If firms don’t dramatically upgrade their cybersecurity practices — and reconsider how much sensitive data they store — more incidents like this will follow.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




