Ransomware victim disclosure
← All victimsFrontier Airlines
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileFrontier Airlines is a major U.S. low-cost carrier operating scheduled flights domestically and internationally. The company generates approximately $1.5B in annual revenue and operates a frequent-flyer program (FRONTIER Miles), loyalty partnerships, and ancillary services including baggage, seats, and vacation bookings.
- Industry
- Airlines & Air Transportation
Attack summary
Severity: critical — Confirmed exfiltration of 2.4 million customer records including significant PII, travel history, and support communications from a major U.S. airline. Data published status and scale of personally identifiable information exposure places this at critical severity.ExfilSquad claims to have exfiltrated approximately 2.4 million records from Frontier Airlines containing significant personally identifiable information, customer support documentation, flight/travel history, complaints, and baggage details.
Data the group says was taken
AI dossier — extracted from the leak post- personally identifiable information (PII)
- customer support cases and communications
- flight and travel booking records
- customer complaint records
- baggage handling details
- customer support email communications
What the group claims
Revenue: $1.5B DATA SUMMARY: 2.4M~ records containing: significant PII, customer support cases, flight and travel information, complaint records, baggage details, and customer support email communications.
Sources
- Victim siteflyfrontier.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

