Air Canada Listed by thegentlemen Ransomware Group
If you are a customer of Air Canada, here’s what is being claimed, and what it would mean for you.
Air Canada was listed on The Gentlemen's leak site. The Gentlemen claims to have stolen internal data. This is the group's claim, not a confirmed finding.
Your account details with Air Canada may now be part of an unverified extortion claim. The Gentlemen ransomware group has listed Air Canada on its leak site, claiming to have taken 51,409 files from the airline. Air Canada has not publicly confirmed the claim as of writing.
Watch Air Canada
Get alerted the next time Air Canada files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Air Canada’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.
The 1086-Day Gap Between Incident and Filing
The record shows the claimed incident occurred on 2023-09-19. The filing was made on September 09, 2026. That is 1086 days — roughly 35.7 months — between the two dates. This unusually long interval is the most concrete detail available. Notification timelines can vary depending on when an investigation concludes and which legal requirements apply, so the gap itself does not prove any specific failure.
What a Leak-Site Listing Actually Establishes
A listing on a ransomware leak site is an accusation, not evidence. Groups like The Gentlemen publish claims to pressure victims into paying, often without independent verification. The claimed 51,409 files could be genuine, recycled from an earlier incident, exaggerated, or fabricated. No regulator, breach-notification service, or third-party index has confirmed that any data left Air Canada’s control. Until such confirmation appears, this remains an unproven claim. Real confirmation would require the company to acknowledge the incident, regulators to list it, or forensic evidence beyond the attacker’s own marketing page.
The Password Field and What It Does Not Reveal
The listing mentions a password field may have been exposed, but the storage scheme is not disclosed. This means we cannot tell whether the passwords were stored using strong, slow-to-crack methods or something weaker. Because the method remains unknown, treat the possibility seriously: if any of your Air Canada passwords were among the claimed files and were poorly protected, they could be at risk. Change your Air Canada password immediately as a precaution, and do not reuse it anywhere else. This single step removes the uncertainty around that specific field.
What the Claim Enables If Files Were Taken
If the files are real, attackers could use Air Canada customer records for targeted phishing, account takeover attempts on linked services, or identity fraud involving travel bookings and Aeroplan accounts. The airline holds passport numbers, payment details, and frequent-flyer data for millions of passengers. Any of those, combined with publicly available information, can make convincing scams more effective. However, no permanent government identifiers such as Social Security numbers were listed in this record, which limits some of the most damaging long-term risks.
The Wider Ransomware Pattern
Ransomware crews routinely post large brands on leak sites whether or not a full compromise occurred. The goal is often to create public pressure and force negotiation. Many such listings later prove overstated or entirely false. For you as a customer, this pattern means every new claim against a company you deal with deserves the same cautious approach: assume the worst until proven otherwise, secure the accounts you control, and wait for official confirmation before assuming your specific data was taken.
Concrete Steps You Can Take Today
- Change your Air Canada password immediately and enable two-factor authentication if not already active. This neutralises the unknown password exposure.
- Review your recent Aeroplan and booking activity for any unfamiliar reservations or changes. Report anything suspicious to Air Canada right away.
- Watch for phishing emails pretending to be from Air Canada about this incident. Delete and report any unsolicited messages asking for credentials or personal details.
- Contact Air Canada directly if you have not received any notification. Because the filing does not state when the incident was discovered, a letter sent to your address at the time of the 2023 incident is the most reliable indicator. If you have moved since September 2023, reach out to them to confirm your status.
GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, identity-chain mapping, and remediation by specialists.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Metro Listed by thegentlemen Ransomware Group
metro.net zoominfo.com/c/metro/351518795 LA Metro is the Los Angeles County Metropolitan Transportat…
EllisDon Corporation Listed by metaencryptor Ransomware Group
EllisDon Corporation is a leading Canadian construction and infrastructure services company. Founded…
Financière d'Uzès Listed by Panzer Ransomware Group
Financière d'Uzès offers a range of financial services tailored for individuals, entrepreneurs, and …