WestJet investigates cyberattack affecting internal systems and app

Organization
WestJet
Exploit
Hacking
Industry
Airline

WestJet, Canada's second largest airline, said it began investigating unauthorized access to its systems on June 13, 2025. The intrusion disrupted internal systems and left some travellers unable to log in to the airline's website and mobile application.

The carrier restricted access to limit the spread of the incident and said it had activated specialised internal teams working with law enforcement and Transport Canada. WestJet stressed that the safety of flight operations was never in question and that flights continued to operate while the technical issues were addressed. Website and app access were restored during the investigation.

At the time of disclosure the airline did not say whether systems had been encrypted or shut down deliberately as a precaution, and no group claimed responsibility. In its September notification WestJet described the perpetrator only as a sophisticated criminal third party.

The airline later confirmed that data had been taken, including names, contact details and information related to passenger reservations and the customer's relationship with WestJet. It said credit card numbers, expiry dates, card security codes and passwords were not involved. WestJet said it was coordinating with the Canadian Centre for Cyber Security, the Office of the Privacy Commissioner of Canada and international law enforcement, and posted a separate notice for U.S. passengers. The timing coincided with warnings that the Scattered Spider group had begun targeting aviation, though WestJet made no attribution.

Updates

  1. WestJet told the Maine Attorney General on 29 September 2025 that about 1.2 million people were affected. The exposed data included names, addresses, dates of birth and government issued identification details, and the airline offered 24 months of monitoring and identity theft protection.

Sources