WestJet, an Alberta Partnership
bd_21b3fba3dd8e7bd9 · schema v1 · pii pii-v1
Full breach record for WestJet, an Alberta Partnership →WestJet, an Alberta Partnership, disclosed a cybersecurity incident identified on June 13, 2025, involving unauthorized access by a sophisticated criminal third party. The incident is now resolved. Personal information potentially affected includes names, dates of birth, mailing addresses, and travel document details (passport/government ID). Credit card numbers, CVVs, and passwords were not compromised. WestJet reported the incident to the FBI and is cooperating with the investigation. Affected US residents were offered 24 months of complimentary credit monitoring and identity theft protection via TransUnion.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6a4e87d06919f5dfNew Hampshire State AGfiled 2025-09-29Verified
- bd_a368060b3708eac5Vermont State AGfiled 2025-09-29Verified
- bd_078db9afda69701fCalifornia State AGfiled 2025-09-30(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Letter%20-%20WestJet.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2025
- Raw hash
- 2e7c3868b5a40bb086a3925b75207720f0ba49adcb1ed9a64bcba5ab9df3ad3f
Reporting entity
- Name
- WestJet, an Alberta Partnershipnorm: westjet an alberta partnership
- Domain
- westjet.com
Victim entity
- Name
- WestJet, an Alberta Partnershipnorm: westjet an alberta partnership
- Domain
- westjet.com
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- Sep 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement, including the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(108 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.