On November 24, 2025, Air Miles España, S.A. appeared on the leak site of the Everest ransomware group after the company’s internal files were allegedly exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Available reporting describes the incident as a classic ransomware operation in which attackers gained access, encrypted systems, and then published a sample of stolen data when the company did not meet their demands. The exact number of people affected remains unknown because the exposed material consists of internal corporate files rather than a straightforward customer database. Public reporting indicates that the files contain a range of sensitive business records that could include customer details, partner contracts, and employee information. The leak site listing carries a countdown timer typical of these groups, after which larger portions or all of the stolen data may be released publicly.
Why This Matters for You and Your Family
When a company that runs a widely used loyalty programme suffers a breach, ordinary customers and their families can be exposed without ever knowing it. Air Miles España collects names, addresses, contact details, purchase histories and travel preferences — exactly the kind of information that makes identity theft, targeted phishing and account takeover easier. If your family uses the programme, your data may now sit in an attacker’s archive. Even if the full dataset has not yet been published, the mere fact that it was taken means criminals have had weeks or months to study it, sell it on underground forums, or combine it with other leaks.
The Doxxing and Identity-Chain Implications
A single breach rarely stays isolated. Criminals routinely cross-reference newly stolen records against older leaks to build complete identity chains. An email address from the Air Miles files can be matched to a username on a gaming platform, a phone number from an earlier breach, and a home address from a data-broker record. Once that chain exists, attackers can move from digital harassment to physical doxxing, SIM-swapping, or extortion. Credential leaks like this one cascade into account takeovers on connected services, including children’s gaming accounts that often reuse the same passwords or recovery emails as family loyalty profiles.