The June 2025 WestJet Cyber Attack: What Happened, What Is Reported and What to Learn
In June 2026, Canadian airline WestJet experienced a cyber attack that caused disruptions to its website and mobile app. While flight operations remained unaffected, internal systems were compromised. The threat group Scattered Spider is suspected of carrying out the attack using social engineering techniques to bypass security protections. This blog explores the full incident, the methods used, the group behind it, and preventive measures organizations can adopt. A table also summarizes the key facts for easier understanding.
Quick answer: In June 2025 WestJet, a Canadian airline, announced a cybersecurity incident that disrupted access to its mobile app and some internal systems while flights kept operating. Media later linked it to the Scattered Spider group after an FBI warning about airlines, but WestJet did not publicly confirm attribution. Check WestJet's own statements for current details.
Key takeaways
- WestJet announced the incident in June 2025. Flight operations continued; the app and some internal systems were affected.
- Attribution to Scattered Spider was reported in media after an FBI warning about airlines. It is not a confirmed finding from WestJet.
- Scattered Spider is known for help desk impersonation, SIM swapping and MFA bypass, so identity processes are the key lesson.
- Defence: strict identity verification for password and MFA resets, phishing-resistant MFA and tight monitoring of help desk actions.
- Always separate confirmed facts from reports when you read incident news.
What happened in the WestJet cyber attack?
In June 2025, WestJet announced it was dealing with a cybersecurity incident. Customers saw problems with the airline's mobile app, and the company said some internal systems were affected. Flights continued to operate. At first the airline said it had no evidence that customer data was compromised, and the investigation was ongoing.
An earlier version of this post gave the year as 2026 in one place. The correct year is 2025. Because the facts changed as the investigation went on, we only state what the airline and public reporting said at that time. Please check WestJet's own updates for the latest on any data exposure.
Who was behind it?
In late June 2025 the FBI warned that the Scattered Spider cybercrime group had begun targeting airlines. Media reports connected WestJet's incident to that activity. WestJet did not publicly confirm who was responsible, so treat attribution as reported, not proven.
What is Scattered Spider?
Scattered Spider (also tracked under names such as UNC3944) is a loose group of English-speaking attackers known for social engineering. Typical methods reported by security firms and agencies include:
- Calling an IT help desk while pretending to be an employee, then asking for a password or MFA reset
- SIM swapping to take over phone numbers used for codes
- Sending phishing messages to staff
- Moving through cloud and identity systems once inside, and sometimes deploying ransomware
Read more in our posts on the FBI warning about airlines, the Aflac social engineering attack and the Qantas data breach.
Why are airlines a target?
Airlines hold large amounts of personal and payment data, depend on many connected systems and cannot afford long outages. Large call-centre and help desk operations also give attackers a human entry point. This is a general pattern, not a claim about how WestJet was breached, because the technical details were not published.
What can organisations learn?
- Harden identity verification. A help desk should never reset a password or MFA based on a voice call alone. Use call-back to a number on file, a manager approval or an in-person check for privileged accounts.
- Use phishing-resistant MFA such as FIDO2 keys or passkeys for staff and especially admins. SMS codes are vulnerable to SIM swapping.
- Limit what one compromised account can reach. Apply least privilege and segment critical systems.
- Monitor help desk and identity events. Alert on MFA method changes, new device enrolments and password resets for privileged users.
- Plan for the outage. Practise incident response, backup restoration and customer communication, including who speaks publicly.
- Train staff with realistic call scenarios, not only email phishing tests.
The MITRE ATT&CK framework describes these social engineering and valid account techniques in detail. Indian organisations can report incidents to CERT-In.
Common mistakes when reading incident news
- Treating a media attribution as a confirmed fact.
- Assuming "no flight impact" means no data impact.
- Learning only the headline and not the control that would have helped.
Next steps
Next steps: to learn how SOC teams detect identity abuse like this, see our Certified SOC Analyst course, and read the FBI warning post.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0