ransomware
Potential
Côte d'Ivoire (CI)
transport
Air Cote d'Ivoire listed by the IncRansom group
Air Cote d'Ivoire
CompanyAir Cote d'Ivoire
CountryCôte d'Ivoire (CI)
Sectortransport
Breach date2026-02-18
People affected100,000
Data typesNot disclosed
<p>On 18 February 2026, the <strong>incransom</strong> ransomware group listed <strong>Air Cote d'Ivoire</strong> on its dedicated leak site in Côte d'Ivoire. The group claims to have exfiltrated data from the organisation, a transport and logistics operator, before publishing the victim on its leak site.</p>
<h2>What the source reveals</h2>
<p>Established in 2012, Air Côte d'Ivoire offers direct and frequent flights. They are based in Abidjan, Ivory Coast.
Employees: 1000
Revenue: 40.5 Million
Industry: Airlines, Airports & Air Services
Phone Number: +225 20251030</p>
<h2>Risks</h2>
<ul>
<li>Exposure of customer travel records, booking data, cargo manifests, and payment information</li>
<li>Operational disruption to scheduling, routing, and fleet management systems</li>
<li>Fraud targeting customers using stolen itineraries, personal data, and travel patterns</li>
<li>Supply chain cascade effects if logistics data disruption impacts dependent industries</li>
<li>Permanent loss of data integrity if backups were also compromised or encrypted</li>
<li>Regulatory and legal consequences depending on data protection laws in the affected jurisdictions</li>
</ul>
<h2>What remains unknown</h2>
<ul>
<li>the volume and specific data types exfiltrated from the organisation</li>
<li>the date of the initial intrusion and the attack vector used</li>
<li>whether the organisation engaged with the attackers or paid any ransom demand</li>
</ul>
<h2>Conclusion</h2>
<p>Ransomware attacks on transport organisations can disrupt operations and expose sensitive data across supply chains. The affected organisation should conduct a thorough forensic investigation, notify relevant regulatory authorities, and communicate transparently with affected stakeholders. Organisations in Côte d'Ivoire should review their ransomware preparedness, including offline backup verification and incident response testing.</p>