On May 06, 2024, French helicopter maintenance company Rotor Team appeared on the leak site operated by the spacebears ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the approved PART145 workshop, which specializes in maintenance, overhaul, painting, and avionics modifications for models including Bell 429, Robinson R44, and Eurocopter H130 aircraft. The number of individuals whose data may have been exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Rotor Team
Get alerted the next time Rotor Team files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Rotor Team’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The spacebears leak site entry, first observed on 6 May 2024, states that internal files were exfiltrated following a ransomware deployment. It does not quantify the volume of data taken, list specific record counts, or name the exact files involved. The disclosure presents Rotor Team, established in 2011 and employing 33 staff across bases at Annecy airport, as the victim. No ransom demand figure or payment deadline is shown in the public listing. The incident is presented as a completed extortion attempt with data now published for anyone to download.
Why This Matters for You and Your Family
When a specialized aviation maintenance provider suffers a breach, the information stolen can easily include details that reach ordinary customers, contractors, pilots, and their families. Maintenance records, contact information, billing data, and correspondence often contain full names, addresses, phone numbers, email accounts, and sometimes passport or pilot license copies. Once these details leave the company’s control, they become permanent currency for identity thieves. Even if you have never flown a helicopter, if you or any member of your family has done business with Rotor Team or similar specialist firms, your information could now sit in an easily searchable archive.
Internal files exfiltrated in such attacks frequently hold scanned contracts, insurance documents, and communication logs that link personal identities to specific addresses and phone numbers. The exposure creates a long-term risk because criminals rarely delete what they have stolen.