Air France and KLM confirm customer data stolen in third-party breach
Both airlines said the data leak originated with a third party supplier
Hackers have gained access to the personal data of potentially hundreds of KLM and Air France customers following a supply chain attack.
News of the breach first appeared on the KLM website in Dutch, and an Air France-KLM spokesperson confirmed the situation, saying the intrusion happened last week (week commencing 28 July 2025).
In a statement to ITPro, a spokesperson said: “Air France and KLM confirm that they are investigating a fraudulent access to the data of some of our customers.
“An unusual activity was detected on a third-party platform used by our contact centers, which led our IT security team, together with the third-party system involved, to swiftly implement corrective measures to put an end to the incident.”
Protective measures have been taken to stop the same thing happening again, the spokesperson confirmed, adding that “no sensitive data such as password, travel data, Flying Blue Miles balance, passport or credit card numbers were disclosed”.
The breach only affects Air France and KLM customers, and both airlines are in the process of contacting these individuals. Customers are advised to be mindful of suspicious emails and phone calls in the wake of the incident.
The affected supplier has not been named for security reasons. However, KLM has reported the incident to the Dutch data protection regulator (Autoriteit Persoonsgegevens), while Air France has contacted the French equivalent (CNIL).
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
In a statement given to ITPro, a spokesperson for CNIL confirmed it has been notified of the breach and that affected individuals have been contacted.
"The CNIL is in the process of analyzing the notification," the spokesperson said. "The data involved are: Name, surname, contact information, Flying Blue membership number and status, and the subject of questions sent to the company by email."
The latest in a long-line of supply chain attacks
Supply chain attacks have become an increasingly popular method of compromise for cyber criminals.
In 2024, security firm Checkmarx revealed that 63% of companies had been the victim of a supply chain attack in the previous two years, while 75% of organizations using open source code packages said they were concerned or very concerned about software supply chain security.
Research also revealed in 2024 that nearly all (97%) of the top 100 US banks were hit by third party data breaches such as the one affecting Air France-KLM, with a similar number subject to fourth-party breaches (suppliers to their suppliers).
SecurityScorecard’s 2025 Global Third-Party Breach Report meanwhile found that the Netherlands – home to KLM – was one of the countries where businesses were most likely to suffer a third-party breach, coming in second after Singapore.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Netgear ramps up enterprise focus with new partner programNews The new Netgear Drive Partner Success Program introduces new tools and resources to help partners drive growth and profitability
-
Rogue cyber pros charged amid ransomware allegationsNews The attackers are alleged to have demanded ransoms of up to $10 million
-
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
-
Red Hat reveals unauthorized access to a GitLab instance where internal data was copiedNews Crimson Collective has claimed the attack, saying it has accessed more than 28,000 Red Hat repositories
-
Google warns executives are being targeted for extortion with leaked Oracle dataNews Extortion emails being sent to executives at large organisations appear to show evidence of a breach involving Oracle's E-Business Suite
-
Harrods rejects contact with hackers, after 430,000 customer records stolen from third-party providerNews The luxury department store has denied any link to a failed attack on its systems in May
-
Kido nursery hackers threaten to release more details – along with the personal data of 100 employeesNews The attack is the first to be claimed by the new threat group 'Radiant'
-
Average Brit hit by five data breaches since 2004News While the number of breaches has fallen, the UK has been the worst-hit country in Northern Europe since 2004
-
Personal data taken in Oxford City Council cyber attacknews The personal data of election workers has been accessed, but the council says it moved quickly to limit the effects of the breach
-
Supplier hack leaks UBS data – including CEO's phone numberNews Chain IQ incident could hit Swiss banking sector hard in "grim reminder" of risk of third-party breaches