CSIDB logo
Incident

Inflite The Jet Centre

Incident posture

Attack window
Nov 2025
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 01:54

Linked entities

Victim
Inflite The Jet Centre
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Aug 2025
Disclosed
Aug 2025
Resolved
Pending

Summary

Inflite The Jet Centre, a ground‑handling subcontractor at London Stansted airport, experienced a cyber‑security incident in which unauthorized access to email accounts exposed personal data including names, passport details and Arap reference numbers for up to 3,700 individuals who had been resettled in the UK. The company reported the breach to the Information Commissioner’s Office and stated that the incident was confined to email systems, with no evidence of public disclosure or compromise of government networks. A separate earlier incident had exposed the details of nearly 19,000 people who had sought relocation to the UK under the same resettlement scheme.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 16 August 2025 the BBC reported that Inflite The Jet Centre, a ground‑handling services provider at London Stansted airport, had suffered a cyber‑security incident. The incident involved unauthorised access to a small number of the company’s email accounts that contained basic personal information. Inflite stated that it believed the scope of the breach was limited to email accounts only and that it had reported the matter to the Information Commissioner’s Office. The Information Commissioner’s Office confirmed to the BBC that it had received a breach report from Inflite.

The compromised emails held the names, passport details (including name, date of birth and passport number) and Afghan Relocations and Assistance Policy reference numbers of up to 3,700 Afghans who had been resettled in the UK between January and March 2024 under a scheme for those who worked with British troops. The same data also concerned British military personnel and former Conservative government ministers. An email sent by the Afghan resettlement team warned affected families that their personal information may have been exposed, specifying the passport and Arap details that could be involved. The UK government said the breach had not posed any threat to individuals’ safety, had not compromised any government systems and that there was currently no evidence that any of the data had been released publicly.

In response to the incident, a government spokesperson noted that they had been notified of a third‑party sub‑contractor to a supplier experiencing a cyber security incident involving unauthorised access to emails containing basic personal information and said they were going above and beyond legal duties in informing potentially affected individuals. Inflite’s statement reiterated that the breach was confined to email accounts and that it had been reported to the ICO. Following the BBC’s Newsnight interview with the son of an Afghan special forces member who feared deportation after his family’s data was leaked, the Ministry of Defence stated that it was honouring commitments to all eligible individuals who pass the required security and entry checks for relocation. Former officials and politicians, including Sir Mark Lyall Grant, Kwasi Kwarteng and Helen Maguire, described the breaches as embarrassing, serious and indicative of inadequate security standards, with Maguire calling for an immediate, fully independent investigation.

Sources

Sources available to members: 1 source.

CSIDB