{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password"},"incident":{"slug":"2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password","title":"WestJet breach of 1.2 million passengers began with a help desk password reset","date":"2025-06-13","date_precision":"day","year":2025,"victim_org":"WestJet","sector":"Transportation & Logistics","country":"Canada","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1200000,"threat_actor":null,"summary":"Canadian airline WestJet disclosed a cyberattack on 13 June 2025 and, after completing its investigation on 15 September, confirmed that roughly 1.2 million customers were affected. Stolen data included names, dates of birth, mailing addresses, passport and government ID documents, travel bookings, loyalty details and co-branded Mastercard information. Credit card numbers, CVVs and passwords were not taken. No formal attribution has been made, though the attack fell inside a wave of aviation-sector intrusions.","how_it_worked":"The attackers used social engineering to have an employee's password reset, then signed in to the corporate network through Citrix. The pretext was that of a legitimate employee locked out of their account, and the identity impersonated was a staff member whose details had been researched beforehand. The trust signal abused was the help desk's willingness to restore access on the strength of knowledge-based answers, and the pressure applied was a worker unable to do their job. From that foothold the intruders moved into the Windows domain and Microsoft cloud tenant and exfiltrated passenger records over several days before detection.","lessons":"Identity-proofing at the service desk, using video verification or a manager-approved out-of-band challenge before any password or MFA reset, is the single control that would have stopped this.","confidence":"Confirmed","sources":[{"title":"WestJet data breach exposes travel details of 1.2 million customers","url":"https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/","publisher":"BleepingComputer"},{"title":"Data breach at Canadian airline WestJet affects 1.2M passengers","url":"https://techcrunch.com/2025/10/01/data-breach-at-canadian-airline-westjet-affects-1-2m-passengers/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-westjet-breach-of-1-2-million-passengers-began-with-a-help-desk-password"}}