Data leak

Iberia (IAG) Third-Party Vendor Loyalty Programme Breach

📅 2025-10-15
Primary Source ↗

Incident Details

Iberia, the Spanish national airline and subsidiary of IAG (International Airlines Group), disclosed in November 2025 that a third-party vendor breach had exposed loyalty programme member data. The compromised data included Iberia Plus loyalty card member names, email addresses, and loyalty card identification numbers. Iberia notified affected members and filed notifications with Spain’s AEPD (Agencia Española de Protección de Datos).

Technical Details

Initial Attack Vector
A third-party vendor used by Iberia was compromised, exposing customer loyalty programme data

Timeline

  1. 2025-10-15 Breach occurred
  2. 2025-11-20 Publicly disclosed
  3. 2025-11-20 Customers notified