
Cyber attack on Hawaiian Airlines: Passenger data in concern, airline retaliates
Cyber attack on Hawaiian Airlines: HONOLULU, Hawaii (29 June 2025) – Hawaiian Airlines, the Pacific’s flagship airline, has been hit by a serious cybersecurity incident that has led to the compromise of personal data of millions of passengers. The incident came to light earlier this week and has been described as an “advanced” cyberattack targeting the airline’s internal IT systems.
Description and impact of the event:
- Nature of attack: Preliminary investigations suggest that hackers exploited a complex weakness in the airline’s network security. Experts suspect a “ransomware” attack, where attackers may have demanded ransom by encrypting systems or stealing data. The airline has not yet confirmed the ransom demand.
- Affected data: Hawaiian Airlines has said in its initial assessment that the attackers may have gained access to sensitive information such as passenger names, email addresses, phone numbers, and in some cases passport numbers. The possibility of compromise of credit card details (which are stored in secure payment gateways) is low, but has not been completely ruled out. An official forensic audit is underway.
- Travel operations: The airline has stressed that flight operations have not been directly affected by the incident. Flights are operating on schedule, and there is no impact on passenger safety. However, some internal administrative systems and customer service portals may be temporarily disrupted as security is restored.
- Number of passengers: It is believed that millions of passengers who have booked with the airline over the past several years may be affected. The airline is still working to determine the exact number and extent of data affected.

Hawaiian Airlines response:
- Immediate action: The airline said it immediately activated its IT team and specialized cybersecurity forensics experts upon discovery. The affected systems have been isolated from the network to limit the damage.
- Notification to authorities: The Federal Bureau of Investigation (FBI), the US Department of Homeland Security (DHS), and Hawaii state authorities have been notified of the incident and are cooperating with the investigation.
- Notification and assistance to passengers: The airline has issued an official statement informing passengers about the incident. They plan to notify affected individuals individually and provide support services, such as credit monitoring, as soon as those affected are fully identified.
- CEO statement: Hawaiian Airlines CEO Peter Ingram said in a video message, “We deeply apologize to our passengers and partners for this cyber incident. Our team is working on it all the time. Our top priority is to protect passenger data and complete the investigation. We will remain transparent and provide necessary assistance to those affected.”
Advice for travellers:
- Be cautious: Be alert for official communications (email or postal mail) from Hawaiian Airlines. Be cautious of any unexpected communications via phone call, text message or email, especially if they ask for personal information or payment details. Airlines do not usually ask for sensitive information in this way.
- Change password: Change your password for the Hawaiian Airlines website or app immediately. If you have used the same password elsewhere, change it there as well. Use strong, unique passwords.
- Keep an eye on credit report: Check your bank and credit card statements carefully for suspicious activity. Consider asking for a free copy of your credit report from a credit bureau (AnnualCreditReport.com). You may also consider a credit freeze.
- Contact the airline directly: Contact Hawaiian Airlines directly through its official website (HawaiianAirlines.com) or customer service numbers if you have any questions or concerns. Do not trust any third party or unverified links.
Future Challenges:
The incident is another reminder of the growing threat of cybersecurity to the global aviation industry. Hawaiian Airlines now faces several challenges:
- Completing a full investigation: Determine the source of the attack, the exact impact, and the identity of the attackers.
- Rebuilding passenger confidence: Reassure passengers affected by the data breach and take concrete steps to protect them.
- Investing heavily in security: Dedicating additional resources to fully strengthen our cybersecurity infrastructure to prevent similar incidents in the future.
- Regulatory and legal processes: Deal with potential regulatory investigations and class action lawsuits that may be filed on behalf of passengers.
Hawaiian Airlines has taken crisis management seriously and has pledged to share information. However, the full impact and long-term consequences of this incident are not yet clear. Affected passengers are advised to remain vigilant and follow security advice provided by the airline. This incident underscores the importance of personal data security and the need for businesses to remain vigilant against ever-evolving cyber threats. Click here for more information