Ransomware crew says it stole 51,409 Air Canada files

Published

The extortion crew that calls itself The Gentlemen added Air Canada to its leak site on 9 September and says it is holding 51,409 files taken from the country's flag carrier. Air Canada has not confirmed that any data was stolen, and the listing on its own does not prove that any was.

That distinction is the whole story for now. A leak site entry is an advertisement, not evidence.

A large number with little behind it

The entry was recorded by the tracker ransomware.live at 22:08 UTC on 9 September, filed against the airline's own domain under the transportation sector, with an attack date of the same day. That file count is the only figure the crew has attached to it. The tracker shows no downloadable data with the entry, though it states that it indexes only publicly visible information and does not host stolen files, so that absence cuts neither way. You can read the tracker's record of the claim directly.

The airline is a substantial target by any measure, with roughly 37,000 employees and 45.3 million passengers carried in 2025. IntelFusions found no public statement from Air Canada addressing the claim, and has not independently verified it. Anyone reading this as a confirmed breach is reading it wrong.

There is one independent pointer that something is being discussed. AhnLab's ASEC research team listed a Gentlemen attack on an unnamed Canadian airline in its weekly ransomware and dark web roundup. ASEC does not name the carrier, so that corroborates the shape of the claim rather than its target.

The crew behind the post

The Gentlemen is a ransomware as a service operation that emerged in mid 2025 and grew quickly by offering affiliates an unusually generous 90 percent share of what they extort. Microsoft tracks its operators as Storm-2697. IntelFusions has logged 629 claims from the group across 70 countries, 100 of them in the past 30 days and 25 in the past week, which puts it among the highest volume crews currently operating. It briefly held the top spot before Qilin took it back in August.

Volume alone is not a reason to believe any single post. It is a reason to expect more of them.

Two days from break-in to encryption

What makes the group awkward for defenders is speed. IntelFusions reported on 1 September that Gentlemen affiliates have moved from initial access to encryption inside two days, which leaves very little room for a slow detection and response cycle. The affiliates' documented way in is exposed edge infrastructure, meaning internet facing appliances such as VPN gateways and remote access devices, rather than anything exotic.

No patch to apply, so harden the edge

Nothing in this claim changes the standing advice, and there is no fix to install here because no vulnerability has been named. Inventory and patch internet facing appliances, enforce multi factor authentication on every remote access path, and rehearse the response plan so that a two day window is survivable. For context on the region, Canada has absorbed 36 leak site claims in the past 30 days and transportation has taken 42 worldwide, so neither the country nor the sector is being singled out.

The next move belongs to the crew. If it publishes samples, the claim becomes checkable. If it goes quiet, this will join the large pile of leak site posts that were never substantiated either way.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions