Ransomware victim disclosure
← All victimsFlydubai
Claimed by Everest · listed 6 hours ago
Status timeline
- ListedOct 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- United Arab Emirates
- Sector
- Transportation
- Listed on leak site
- Oct 6, 2026
About the victim
AI dossier — public-source company profileFlydubai is a government-owned low-cost airline based in Dubai, United Arab Emirates, operating since 2008. It provides passenger and cargo flight services across the Middle East, Africa, Asia, and Europe, functioning as a budget carrier that complements Emirates by expanding connectivity to underserved and emerging markets.
- Industry
- Aviation & Air Transportation
- Address
- Dubai International Airport, Dubai, United Arab Emirates
- Founded
- 2008
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed status confirmed), indicating successful exfiltration. However, without specifics on data type, volume, or operational impact, and given the absence of detailed proof inventory, a medium rating reflects the confirmed disclosure against a critical infrastructure entity (airline) without confirmed sensitive data categories.The Everest group claims to have conducted an attack on Flydubai and published data. The specific nature of the compromise (encryption, exfiltration, or both) and data categories at stake are not detailed in the available leak post excerpt.
Original description
AI-summarised, not from the leak postFlydubai is a government-owned low-cost airline based in Dubai, United Arab Emirates. Founded in 2008, it operates within the aviation and air transportation industry, providing passenger and cargo flight services across the Middle East, Africa, Asia, and Europe. The airline operates from Dubai International Airport and serves as a budget carrier complementing Emirates, expanding connectivity to underserved and emerging markets globally.
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

