Air France-KLM Group announced that thousands of customers from the United Kingdom have been exposed to unauthorized access following a data breach on an external platform used for customer service. The company confirmed that the attack was halted after detection.
The Group stated that its operational systems were not affected by the attack and that the breach was limited to the customer service platform. “Our IT security teams, working with the relevant third parties, quickly stopped the unauthorized access and took necessary measures to prevent recurrence,” the statement said.
Serving approximately 98 million passengers in 2024, Air France-KLM operates flights to 300 destinations worldwide. The Group warned account holders to be vigilant against increasing phishing emails and fraud attempts following the breach.
KLM informed customers, stating, “It is crucial for our customers to be extra cautious about suspicious emails and phone calls.”
Cybersecurity experts also noted the effective management of the breach. Javvad Malik, a security awareness advocate at KnowBe4, said, “Customers should remain alert to sophisticated fraud tactics, and organizations must continuously monitor parties accessing their data.” Boris Cipot, senior security engineer at Black Duck, commented, “Air France and KLM’s swift response is an important example of effective breach management.”
For customer safety, the airline urges all users to closely monitor their account activities and to contact official channels if any suspicious activity occurs.



