Skip to main content

Company intelligence

Envoyair cybersecurity incidents and threat signals

envoyair.com

Envoyair logo

This company page brings together public reporting currently associated with Envoyair. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

June 25, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Envoyair. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Envoyair

Envoyair logoRansomware
Medium

American Airlines subsidiary Envoy Air confirms Oracle data theft attack by Clop ransomware

Envoy Air, a regional airline carrier owned by American Airlines, confirmed a data breach stemming from a cyberattack that exploited a zero-day vulnerability (CVE-2025-61882) in Oracle's E-Business Suite application. The Clop ransomware group claimed responsibility for the attack, which was part of a broader extortion campaign. Envoy Air stated that a limited amount of business information and commercial contact details may have been compromised, but no sensitive customer data or flight operations were affected.

Envoyair

FAQ

Questions about Envoyair cybersecurity reporting

What does the Envoyair page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Envoyair.

Does every mention of Envoyair appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.