Cybercriminal group Everest claims to have breached flydubai and stolen thousands of files containing information related to the airline’s pilots, employees, and flight operations.
The attackers say they obtained approximately 4.36 GB of information consisting of more than 16,500 files. The alleged material includes flight operations documents, crew training information, and personnel records.
Some of the files are claimed to contain details about pilots, including training and employment-related information. Everest has also claimed that proprietary Boeing software source code was included among the stolen material.
However, the scale and authenticity of the alleged leak have not been independently verified. There is currently no public confirmation from flydubai establishing that Everest successfully breached its systems or that all of the information described by the group was stolen.
It is also unclear how the attackers allegedly gained access. No exploited vulnerability, compromised account, third-party service or other initial entry point has been publicly identified.
Everest has previously used stolen corporate information as leverage against organizations, publishing samples or threatening wider releases if its demands are not met. As with other extortion groups, however, claims posted by the attackers cannot automatically be treated as proof of a breach.
If the flydubai files are authentic, information involving pilots and airline operations could create additional risks beyond the immediate exposure of employee data. Such material could potentially be exploited for highly targeted phishing and impersonation attempts.
For now, the incident remains an unverified cybercriminal claim. Neither the alleged 4.36 GB data theft nor the reported contents of the files should be considered confirmed until flydubai, investigators, or independent researchers provide further evidence.