Data breach
Air Miles España (Travel Club)
- Records
- 2,657,513
- Breach date
- 8 December 2025Estimated
- Added
- 12 December 2025
What was exposed
4 types of data
- Dates of birth1
- Email addresses1
- Names1
- Gender1
About this breach
The Everest ransomware group has claimed a breach of Air Miles España S.A., the Spanish company that operates the Travel Club loyalty program, and published data allegedly taken from the company. According to the Breachsense breach tracking service, the group listed Travel Club among its victims on November 25, 2025, claiming roughly 131 GB of stolen data. As reported by Hackread, the claim appeared alongside attacks on other Spanish targets, including Iberia Airlines. The investigation team indexed the listing on December 12, 2025, and estimates the leaked dataset contains 2,657,513 rows. The estimated attack date in our records is December 8, 2025, though no individual or group has formally claimed the breach in our own investigation data.
Breach Timeline
November 25, 2025: The Everest group's claim against Air Miles España, operator of Travel Club, was publicly reported, including a listing of roughly 131 GB of alleged stolen data.
December 2, 2025: Travel Club sent customers a notice about unauthorized access to data held by a provider, as reported by RedesZone.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, dates of birth, and gender.
Travel Club's own notice to customers, reviewed by RedesZone, described the exposed data slightly differently. It said the unauthorized access involved the customer's name, though not surnames, plus email address, date of birth, loyalty card number, and the point balance on a specific date. The company stated that passwords, login names, national ID numbers, and physical addresses were not exposed, and that the incident stemmed from a vulnerability at a provider Travel Club uses.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Even without passwords, this combination of data is useful to scammers. Someone holding your name, email, date of birth, and loyalty card number can send convincing messages that appear to come from Travel Club or its partners, such as retailers, fuel stations, and airlines in the program. A message that references your point balance or card number looks far more legitimate than a generic phishing email.
The main risks are phishing emails that try to trick you into entering your Travel Club credentials on a fake site, calls or messages impersonating customer service, and attempts to hijack loyalty accounts to redeem accumulated points. If an attacker gains access to an account, the points themselves can be spent, and the linked email could be used to reset passwords on other services where you reused it. Travel Club itself warned customers to expect this kind of follow-up activity after the notice.
What Is Air Miles España (Travel Club) Doing in Response?
According to the customer notice reported by RedesZone, Travel Club said it activated security protocols after learning of the issue, limited access to the affected computer system, and began continuous monitoring of accounts and customer data for suspicious activity. The company also said it notified the Spanish Data Protection Agency (AEPD) and Spanish law enforcement, and was investigating internally and with its providers. Travel Club stated that its services were not disrupted because the problem sat with a supplier rather than its own systems. It also advised customers to enable two-factor authentication on their accounts, and said it never sends links or downloadable files in its emails.
What Should You Do If You Were Affected?
Be skeptical of any email, text, or call about this incident that asks you to click a link, download a file, or confirm personal or banking details. Verify through Travel Club's official website or app instead.
Enable two-factor authentication on your Travel Club account. The company offers this through its website.
Change your Travel Club password, and change it anywhere else you may have reused it.
Check your point balance and account activity for redemptions you did not make, and report anything unusual to Travel Club.
Treat unexpected emails that mention this breach as suspect. Attackers often use real breach details to make fake security warnings look authentic.
