[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7epzs3xbapvs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":16,"seoTitleEn":34,"seoDescription":16,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488253ab","tapair-portugal","TAP Air Portugal Data Breach","tap-air-portugal","flytap.com","2022-08-25T00:00:00.000Z","2022-09-23T05:33:05.000Z","2026-07-03T14:58:02.905Z","2026-07-18T23:59:04.494Z","Third party breach","",[],6083479,"known",null,"unknown","Critical",[24,25,26,27,28,29,30,31,32],"Dates of birth","Email addresses","Genders","Names","Nationalities","Phone numbers","Physical addresses","Salutations","Spoken languages","\u003Cp>The TAP Air Portugal data breach is a large-scale customer data incident linked to the ransomware attack on the Portugal-based airline TAP Air Portugal in August 2022. The record includes 6,083,479 unique email addresses. Data classes cover dates of birth, email addresses, gender information, names, nationalities, phone numbers, physical addresses, salutations, and spoken languages.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>Airline data is more sensitive than ordinary communication information because it carries the context of travel, country, language, and identity. When fields such as name, date of birth, nationality, phone, and address are combined with email, fake ticket, check-in, baggage, loyalty program, or passport update messages can become more convincing.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, address, username, or location come together, attackers can prepare messages that appear to have a real service relationship with the user. This information alone does not always mean account takeover; however, it can be used for phishing, fake support requests, delivery notifications, account verification, and personalized fraud flows. Password or full payment card fields are not listed in the record. Nevertheless, personal data that appears to be associated with travel history can be used in passport- or visa-themed social engineering. The user should specifically verify flight and loyalty program messages through the official channel.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The date of the incident is recorded as August 25, 2022, and the number of affected email accounts is 6,083,479. Reliable sources report that TAP Air Portugal was subjected to a ransomware attack and that customer data was later published. The exposed fields correspond to personal information such as name, gender, date of birth, phone number, and physical address.\u003C\u002Fp>\u003Cp>When explaining the scope, fields not listed under this record such as payment card or passport number should not be added. The amount of raw data and the number of unique emails may vary. The correct risk to the user is that personal fields related to risk, travel, and identity can be misused.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are TAP Air Portugal customers, loyalty program members, passengers who make reservations, and individuals who share flight contact information. Nationality and language fields can facilitate the preparation of fake messages appropriate for the user's country.\u003C\u002Fp>\u003Cp>Frequent travelers are accustomed to messages about check-in, baggage fees, flight cancellations, refunds, mileage points, or passport verification. Messages that come with a real name and phone number may seem official. Therefore, urgent payment or identity document requests should be carefully examined.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching field should check that they use a unique password for their TAP account and travel accounts used with the same email. Loyalty program accounts, registered contact information, and suspicious flight notifications should be reviewed through the official application.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address on different platforms makes it easier to combine data from different breaches; therefore, using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Unnecessary registered addresses and old phone numbers should be removed from airline and travel accounts. Loyalty program accounts can be high value; therefore, strong passwords, two-step verification, and transaction alerts should be used.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result increases the risk of travel-themed targeted messaging. A negative result means there is no match within this record; the same email address should also be checked with other airlines or travel services.\u003C\u002Fp>","TAP Air Portugal Data Breach (6.1 Million Reported Records)","TAP Air Portugal Data Breach. 6.1 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fflytap_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"TAP Air Portugal","Airline","Portugal"]