The June 2025 WestJet Cyber Attack: What Happened, What Is Reported and What to Learn

In June 2026, Canadian airline WestJet experienced a cyber attack that caused disruptions to its website and mobile app. While flight operations remained unaffected, internal systems were compromised. The threat group Scattered Spider is suspected of carrying out the attack using social engineering techniques to bypass security protections. This blog explores the full incident, the methods used, the group behind it, and preventive measures organizations can adopt. A table also summarizes the key facts for easier understanding.

Jul 21, 2025 - 11:16
Updated: 8 days ago
104.9k
The June 2025 WestJet Cyber Attack: What Happened, What Is Reported and What to Learn

Quick answer: In June 2025 WestJet, a Canadian airline, announced a cybersecurity incident that disrupted access to its mobile app and some internal systems while flights kept operating. Media later linked it to the Scattered Spider group after an FBI warning about airlines, but WestJet did not publicly confirm attribution. Check WestJet's own statements for current details.

Key takeaways

  • WestJet announced the incident in June 2025. Flight operations continued; the app and some internal systems were affected.
  • Attribution to Scattered Spider was reported in media after an FBI warning about airlines. It is not a confirmed finding from WestJet.
  • Scattered Spider is known for help desk impersonation, SIM swapping and MFA bypass, so identity processes are the key lesson.
  • Defence: strict identity verification for password and MFA resets, phishing-resistant MFA and tight monitoring of help desk actions.
  • Always separate confirmed facts from reports when you read incident news.

What happened in the WestJet cyber attack?

In June 2025, WestJet announced it was dealing with a cybersecurity incident. Customers saw problems with the airline's mobile app, and the company said some internal systems were affected. Flights continued to operate. At first the airline said it had no evidence that customer data was compromised, and the investigation was ongoing.

An earlier version of this post gave the year as 2026 in one place. The correct year is 2025. Because the facts changed as the investigation went on, we only state what the airline and public reporting said at that time. Please check WestJet's own updates for the latest on any data exposure.

Who was behind it?

In late June 2025 the FBI warned that the Scattered Spider cybercrime group had begun targeting airlines. Media reports connected WestJet's incident to that activity. WestJet did not publicly confirm who was responsible, so treat attribution as reported, not proven.

What is Scattered Spider?

Scattered Spider (also tracked under names such as UNC3944) is a loose group of English-speaking attackers known for social engineering. Typical methods reported by security firms and agencies include:

  • Calling an IT help desk while pretending to be an employee, then asking for a password or MFA reset
  • SIM swapping to take over phone numbers used for codes
  • Sending phishing messages to staff
  • Moving through cloud and identity systems once inside, and sometimes deploying ransomware

Read more in our posts on the FBI warning about airlines, the Aflac social engineering attack and the Qantas data breach.

Why are airlines a target?

Airlines hold large amounts of personal and payment data, depend on many connected systems and cannot afford long outages. Large call-centre and help desk operations also give attackers a human entry point. This is a general pattern, not a claim about how WestJet was breached, because the technical details were not published.

What can organisations learn?

  1. Harden identity verification. A help desk should never reset a password or MFA based on a voice call alone. Use call-back to a number on file, a manager approval or an in-person check for privileged accounts.
  2. Use phishing-resistant MFA such as FIDO2 keys or passkeys for staff and especially admins. SMS codes are vulnerable to SIM swapping.
  3. Limit what one compromised account can reach. Apply least privilege and segment critical systems.
  4. Monitor help desk and identity events. Alert on MFA method changes, new device enrolments and password resets for privileged users.
  5. Plan for the outage. Practise incident response, backup restoration and customer communication, including who speaks publicly.
  6. Train staff with realistic call scenarios, not only email phishing tests.

The MITRE ATT&CK framework describes these social engineering and valid account techniques in detail. Indian organisations can report incidents to CERT-In.

Common mistakes when reading incident news

  • Treating a media attribution as a confirmed fact.
  • Assuming "no flight impact" means no data impact.
  • Learning only the headline and not the control that would have helped.

Next steps

Next steps: to learn how SOC teams detect identity abuse like this, see our Certified SOC Analyst course, and read the FBI warning post.

Related reading

Frequently Asked Questions

In June 2025, WestJet announced a cybersecurity incident that affected access to its mobile app and some internal systems. Flights continued to operate. The airline said the investigation was ongoing, so check its updates for data exposure details.

Media reports linked it to the Scattered Spider group after an FBI warning about airlines in June 2025. WestJet did not publicly confirm attribution, so it should be treated as reported, not proven.

WestJet said flight operations continued normally. The disruption was to its mobile app and some internal systems. The airline did not say flights were cancelled because of the incident.

Scattered Spider is a cybercrime group, also tracked as UNC3944, known for social engineering such as help desk impersonation, SIM swapping and MFA bypass. Authorities and security firms have linked it to attacks on several industries.

Verify identity with a call-back to a known number, manager approval or in-person check before any password or MFA reset. Use phishing-resistant MFA, least privilege and alerts on MFA changes for privileged accounts.

Early statements said there was no evidence of customer data compromise, but investigations can change. Please check WestJet's most recent official statements, as this article cannot confirm the current position.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.