Skip to content

ita lufthansa ita airways

Here’s how hackers fly on Ita Airways

Hackers reportedly breached Ita Airways' defense systems, stealing a significant amount of data related to customers enrolled in the "Volare Loyalty Program." The airline itself disclosed the incident, advising users to be cautious of any targeted phishing emails or SMS messages.

In the same hours when the former sky startup born from the ashes of the flag carrier Alitalia acquired by Lufthansa announced the first profit in its history (amounting to 209 million euros, an improvement of 436 million compared to 2024. It is the second consecutive year of positive EBIT, rising to 25 million, +22 million over 2024, and total revenues of 3.2 billion, in line with the previous year, and EBITDA improved by 67 million to 404 million), suspicion also arose that it had been the victim of a hacker attack.

HACKERS ON BOARD ITA AIRWAYS?

The airline announced a possible breach of its systems through the opening of a dedicated page on its official website: “FAQ Security Event related to the Volare Program.” Browsing through the various pop-up windows reveals that on February 23, 2026, the carrier led by Joerg Eberhart, CEO and General Manager, “received a communication from an unauthorized external party claiming to be in possession of some data related to customers enrolled in the Volare Loyalty Program.”

The communication “shared a sample of data which, based on preliminary checks conducted” by Ita Airways itself “appears consistent with information actually processed within the Volare Program and related communication and marketing activities aimed at customers. According to the current technical analyses, such data seem to refer to historical information from previous periods, and not to updated data or related to recent transactions.”

The company emphasizes that it “immediately activated its internal security incident management procedures and initiated technical checks and analysis activities to reconstruct the methods of the possible unauthorized access, verify the actual extent of the data involved, and adopt the necessary measures to reduce potential risks. ITA Airways has also notified the competent authorities of the event and is continuing with technical investigation activities.”

DATA THAT MAY HAVE ENDED UP IN THE HACKERS’ HAUL

The company also states that “the data that may be affected by the event concern some information processed within the Volare Loyalty Program,” namely “personal and contact data, such as first name, last name, date of birth, email address, and residential address, as well as some information related to the Volare profile, such as membership number, points balance, language and gender indicated in the profile, and the status of marketing and profiling consents.

But Ita Airways also admits that “for some customers, information related to a flight already taken may also be present, such as destination, departure airport, flight identifier, or boarding gate. For members who have associated an American Express card with the Volare Program, the type of card associated (for example Blue, Gold, or Platinum) may also be indicated.” Currently, “No payment card numbers, security codes, bank details, or access credentials to Volare accounts appear to be involved.”

WHAT DO HACKERS DO WITH THIS DATA?

Often hackers contact the company that suffered the theft to try to resell it, usually a futile operation since there is no certainty that the data have not been duplicated countless times to be sold on the dark web where they could be used, as Ita Airways explains, to carry out credible scams: “The nature of the potentially involved data could increase the risk of phishing attempts or fraudulent communications constructed using correct and consistent information with the customer’s profile. In particular, any references to the Volare Program or flights already taken could be used to make emails, SMS, or phone calls seemingly from ITA Airways or commercial partners more credible, aiming to induce the recipient to provide further personal data or make undue payments.”

SUGGESTIONS FOR USERS

For this reason, the company urges not to open suspicious emails and other communications and especially not to click on any links contained therein, as they could inject various types of malware into the device. Users are also advised, “as a precaution, to update their profile password using a strong credential different from those used for other online services.” Ita Airways also recommends “periodically monitoring the Volare profile and reporting any anomalies through official channels.

Back To Top