Ransomware victim disclosure
← All victimsAir Côte d'Ivoire
listed as aircotedivoire.com · Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 19, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- South Africa
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 19, 2026
- Estimated revenue
- $40.5M
About the victim
AI dossier — public-source company profileAir Côte d'Ivoire is the national airline of Côte d'Ivoire, established in 2012 and headquartered in Abidjan. The carrier operates domestic, regional, and international routes, and offers ancillary services including cargo (Cargo Ivoire), a frequent-flyer programme (sMiles), and medical evacuation flights. The airline reported annual revenue of approximately $40.5 million and employs around 1,000 staff.
- Industry
- Airlines & Air Transport
- Address
- Abidjan, Ivory Coast (Côte d'Ivoire)
- Employees
- 1000
- Founded
- 2012
Attack summary
Severity: high — Data has been confirmed as published by the threat actor against a national airline with ~1,000 employees and passenger PII exposure risk; aviation operators handling passenger and financial data represent significant sensitivity, and data_published status confirms exfiltration beyond mere listing.INC Ransom claims to have compromised Air Côte d'Ivoire and has published data (disclosed status: data_published), indicating exfiltration of company data; no specific data categories or volume are enumerated in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate/internal files
- Passenger data (potential)
- Employee records (potential)
- Financial records (potential)
What the group claims
Established in 2012, Air Côte d'Ivoire offers direct and frequent flights. They are based in Abidjan, Ivory Coast. Employees: 1000 Revenue: 40.5 Million Industry: Airlines, Airports & Air Services Phone Number: +225 20251030
Sources
- Victim siteaircotedivoire.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

