All Breaches
June 13, 2025 Verified Sensitive Record Transportation

WestJet 2025 Data Breach

The WestJet 2025 data breach was a cybersecurity incident detected in the Canadian airline's systems on June 13, 2025, in which a sophisticated criminal actor gained unauthorized access and obtained certain data. WestJet confirmed the event in its official U.S. notice, secured systems, launched a forensic investigation, and worked with law-enforcement and regulatory authorities in the United States and Canada.

A source-linked breach record reports approximately 1.2 million affected U.S. customers. The review was completed on September 15, and notices to U.S. residents began around September 29. Information varied by person and could include identity, contact, reservation, travel-document, and WestJet Rewards data. No customer rows were imported into LeakData; importedRecordCount is zero.

How Was the WestJet Breach Confirmed?

The primary source is WestJet's “Notice of Cybersecurity Incident for US Residents” on its own website. The airline directly describes the date of suspicious activity, unauthorized access, confirmation that data was obtained, review and notification process, broad categories involved, specifically excluded fields, and post-incident security measures.

A Massachusetts consumer-notification file confirms the sample individual letter, Rewards fields, card and password exclusions, and 24 months of Cyberscout services. Claim Depot connects the official WestJet page and multiple state attorney-general records and provides the 1.2 million U.S. total, state subsets, and detailed fields. The sources align on the core event and scope.

What Happened Between June 13 and September 15, 2025?

WestJet identified suspicious activity in its systems on June 13. The investigation found that a sophisticated criminal actor had obtained unauthorized access. The airline contained the incident, secured systems, and conducted technical and forensic work with internal and outside specialists. According to its notice, the safety and integrity of airline operations were never in question.

Forensic work confirmed that certain data was obtained from WestJet systems. The organization then analyzed the material by data element and tried to locate current contact information for affected U.S. residents, completing that review on September 15. The public notice does not identify the actor, initial entry method, duration of persistence, or whether files were publicly released.

What Identity and Travel Information Was Involved?

Information varied by person and could include names, dates of birth, mailing addresses, and other contact details. Documents connected with reservations and travel could include a passport number or other government-identification information. Requested accommodations, submitted complaints, and other reservation information describing a person's relationship with WestJet may also have been involved.

Travel-document and reservation context may help an attacker craft targeted messages that appear to know about an upcoming or previous trip. Special-assistance or accommodation requests may enable sensitive inferences, but the source does not confirm a specific medical diagnosis. LeakData does not add an undisclosed route, travel companion, passport image, or clinical field as confirmed data.

What WestJet Rewards and Card-Related Fields Were Involved?

For WestJet Rewards members, the Rewards ID number, points balance on the incident date, and other information linked to use of the account may have been affected. For co-branded WestJet RBC Mastercard customers, a card-type identifier such as “World Elite” and information about changes to a points balance may also have been involved. Those fields can make loyalty-account phishing more convincing.

The official notice expressly excludes important fields: credit-card and debit-card numbers, expiration dates, and CVV codes were not obtained, and guest user passwords were not affected. A card-type identifier is not the actual card number. WestJet said it had no reason to believe points were at risk, although members should still monitor account activity.

How Many People Were Affected and Which Authorities Were Notified?

The source-linked record reports approximately 1,200,000 affected U.S. customers, the value used for pwnCount and totalRecords. State examples include 1,847 Massachusetts, 1,487 Texas, 1,177 South Carolina, 481 Montana, 367 Iowa, 289 New Hampshire, and 240 Maine residents. Those subsets are not added on top of the national figure.

WestJet said it worked with the FBI, Canadian Centre for Cyber Security, Transport Canada, Office of the Privacy Commissioner of Canada, and appropriate state attorneys general. TransUnion, Experian, and Equifax were also notified. The numerical total does not mean individual event records were uploaded to LeakData; importedRecordCount is zero and only verified breach metadata is presented.

How Did WestJet Respond and How Can Travelers Protect Themselves?

WestJet contained the access, increased monitoring, and implemented additional system and data-security measures. Eligible notified customers were offered 24 months of credit monitoring, identity protection, and fraud assistance through Cyberscout. An assistance line at 1-833-294-7065 was provided from 8:00 a.m. to 8:00 p.m. Eastern on weekdays.

Travelers should verify upcoming trips only through the official app or website and should not provide payment-card, travel-document, or login information in unexpected messages claiming to represent WestJet. Rewards activity, credit reports, and account statements should be reviewed for unfamiliar activity; a fraud alert or credit freeze may be appropriate. LeakData does not host, distribute, or make searchable the obtained data.

1.2 Million
Affected Accounts
15
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

15
Personal information
Names
Dates of birth
Mailing addresses
Contact details
Travel document information
Passport numbers
Other government identification information
Reservation and travel information
Requested accommodations
Submitted complaints
Westjet rewards id numbers
Points balances
Credit card type identifiers
Information about points-balance changes

Additional Information

Added DateJuly 27, 2026
Breach DateJune 13, 2025
Domainwestjet.com
SourceOfficial WestJet notice confirming unauthorized system access and acquisition of customer data affecting about 1.2 million U.S. customers
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information