ransomware Credible South Africa (ZA) aviation

South African Airways (SAA) listed by the Inc Ransom ransomware group

South African Airways (SAA)

📅 16 May 2025
CompanySouth African Airways (SAA)
CountrySouth Africa (ZA)
Sectoraviation
Breach date2025-05-16
People affectedNot disclosed
Ransomware groupincransom
Data typespassenger data, booking records, corporate information

Overview

The Inc Ransom group has listed South African Airways (SAA), the state-owned passenger and freight airline, on its leak site. A member of the Star Alliance, SAA is headquartered in Johannesburg. The listing appeared on 16 May 2025.

South African Airways leak listing

What was published

The group claims to have exfiltrated data from the airline. The archive is expected to include passenger records, booking data and corporate information.

Risks for affected individuals

  • Passenger personal data may be exposed.
  • Booking records could enable fraud.
  • Employees' information may be included.

What remains unknown

  • The volume of data exfiltrated.
  • Whether the data has been published.
  • The response status of the airline.

What affected people should do

Passengers should monitor their accounts and be cautious of unsolicited communications. SAA should notify affected passengers and staff, review its systems, and coordinate with aviation authorities on the response.

Sources

  • http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6821f584ba68908013acad75