Skip to content
Back to Blog
high severity September 09, 2026 · 3 min read Unverified claim — what this is

Air Canada Listed by thegentlemen Ransomware Group

If you are a customer of Air Canada, here’s what is being claimed, and what it would mean for you.

Air Canada was listed on The Gentlemen's leak site. The Gentlemen claims to have stolen internal data. This is the group's claim, not a confirmed finding.

Air Canada Listed by thegentlemen Ransomware Group

Your account details with Air Canada may now be part of an unverified extortion claim. The Gentlemen ransomware group has listed Air Canada on its leak site, claiming to have taken 51,409 files from the airline. Air Canada has not publicly confirmed the claim as of writing.

Watch Air Canada

Get alerted the next time Air Canada files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Air Canada’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.

The 1086-Day Gap Between Incident and Filing

The record shows the claimed incident occurred on 2023-09-19. The filing was made on September 09, 2026. That is 1086 days — roughly 35.7 months — between the two dates. This unusually long interval is the most concrete detail available. Notification timelines can vary depending on when an investigation concludes and which legal requirements apply, so the gap itself does not prove any specific failure.

What a Leak-Site Listing Actually Establishes

A listing on a ransomware leak site is an accusation, not evidence. Groups like The Gentlemen publish claims to pressure victims into paying, often without independent verification. The claimed 51,409 files could be genuine, recycled from an earlier incident, exaggerated, or fabricated. No regulator, breach-notification service, or third-party index has confirmed that any data left Air Canada’s control. Until such confirmation appears, this remains an unproven claim. Real confirmation would require the company to acknowledge the incident, regulators to list it, or forensic evidence beyond the attacker’s own marketing page.

The Password Field and What It Does Not Reveal

The listing mentions a password field may have been exposed, but the storage scheme is not disclosed. This means we cannot tell whether the passwords were stored using strong, slow-to-crack methods or something weaker. Because the method remains unknown, treat the possibility seriously: if any of your Air Canada passwords were among the claimed files and were poorly protected, they could be at risk. Change your Air Canada password immediately as a precaution, and do not reuse it anywhere else. This single step removes the uncertainty around that specific field.

What the Claim Enables If Files Were Taken

If the files are real, attackers could use Air Canada customer records for targeted phishing, account takeover attempts on linked services, or identity fraud involving travel bookings and Aeroplan accounts. The airline holds passport numbers, payment details, and frequent-flyer data for millions of passengers. Any of those, combined with publicly available information, can make convincing scams more effective. However, no permanent government identifiers such as Social Security numbers were listed in this record, which limits some of the most damaging long-term risks.

The Wider Ransomware Pattern

Ransomware crews routinely post large brands on leak sites whether or not a full compromise occurred. The goal is often to create public pressure and force negotiation. Many such listings later prove overstated or entirely false. For you as a customer, this pattern means every new claim against a company you deal with deserves the same cautious approach: assume the worst until proven otherwise, secure the accounts you control, and wait for official confirmation before assuming your specific data was taken.

Concrete Steps You Can Take Today

  • Change your Air Canada password immediately and enable two-factor authentication if not already active. This neutralises the unknown password exposure.
  • Review your recent Aeroplan and booking activity for any unfamiliar reservations or changes. Report anything suspicious to Air Canada right away.
  • Watch for phishing emails pretending to be from Air Canada about this incident. Delete and report any unsolicited messages asking for credentials or personal details.
  • Contact Air Canada directly if you have not received any notification. Because the filing does not state when the incident was discovered, a letter sent to your address at the time of the 2023 incident is the most reliable indicator. If you have moved since September 2023, reach out to them to confirm your status.

GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, identity-chain mapping, and remediation by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Air Canada is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High the filing does not enumerate what was exposed
Disclosed September 09, 2026
Last reviewed September 9, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email