HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
WestJet, an Alberta Partnership
bd_6a4e87d06919f5df · schema v1 · pii pii-v1
Full breach record for WestJet, an Alberta Partnership →WestJet notified the New Hampshire Attorney General on September 29, 2025, of a cybersecurity incident discovered on June 13, 2025. A sophisticated criminal third party gained unauthorized access to WestJet's systems, compromising personal information of 289 New Hampshire residents. Affected data included names, dates of birth, mailing addresses, and travel document details (e.g., passport numbers). WestJet engaged forensic investigators, reported the incident to the FBI, and is offering 24 months of complimentary credit monitoring and identity theft protection services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_21b3fba3dd8e7bd9South Carolina State AGfiled 2025-09-29Candidate
- bd_a368060b3708eac5Vermont State AGfiled 2025-09-29Verified
- bd_078db9afda69701fCalifornia State AGfiled 2025-09-30(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/westjet-20250929.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2025
- Raw hash
- d54fa3b9a97ce516bae5e38a55e852fc80f491396e06c0ef03fa4953b3454601
Reporting entity
- Name
- Greenberg Traurig, P.A.norm: greenberg traurig
Victim entity
- Name
- WestJet, an Alberta Partnershipnorm: westjet an alberta partnership
- Domain
- westjet.com
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- Sep 29, 2025
- Notification sent
- Sep 29, 2025
- Affected individuals
- 289
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney GeneralCooperating with FBI investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(108 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.