Ransomware victim disclosure
← All victimsAir Côte d'Ivoire
listed as aircotedivoire.com · Claimed by Incransom · listed 4 months ago
Status timeline
- ListedFeb 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- South Africa
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 19, 2026
- Estimated revenue
- $40.5M
About the victim
AI dossier — public-source company profileAir Côte d'Ivoire is the national airline of Côte d'Ivoire, headquartered in Abidjan. Established in 2012, it operates direct and frequent flights across domestic, regional, and international routes. The airline reported annual revenue of approximately $40.5 million and holds IOSA (IATA Operational Safety Audit) certification.
- Industry
- Airlines & Air Transport
- Address
- Abidjan, Ivory Coast (Côte d'Ivoire)
- Employees
- 1000
- Founded
- 2012
Attack summary
Severity: high — Data has been confirmed published by the ransomware group against a national airline with ~1,000 employees and passenger operations, indicating likely exfiltration of significant business and potentially passenger PII data from a critical transport operator.The Incransom group claims to have attacked Air Côte d'Ivoire and has published data (disclosed status: data_published), suggesting exfiltration of company data. No specific data volume or encryption claim is detailed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Employee records
- Passenger data
- Financial records
- Operational data
- Freight/cargo records
What the group claims
Established in 2012, Air Côte d'Ivoire offers direct and frequent flights. They are based in Abidjan, Ivory Coast. Employees: 1000 Revenue: 40.5 Million Industry: Airlines, Airports & Air Services Phone Number: +225 20251030
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

