VORANT. Threat Intelligence Sign in Get the full feed

Chaos ransomware lists Air Creebec as victim

medium threat transportation

Ransomware.live shows Quebec airline Air Creebec listed as a victim by the Chaos ransomware operation, exposing thousands of user records.

A listing on Ransomware.live identifies aircreebec.ca, the domain of Quebec-based regional carrier Air Creebec, as a victim of the Chaos ransomware group. The entry reports a small number of directly compromised employee accounts alongside a much larger pool of nearly 9,700 compromised user credentials and seven third-party employee credentials, suggesting the exposure may stem partly from infostealer-derived credential leakage rather than a single breach event.

No file hashes, C2 infrastructure, or exploited vulnerabilities are disclosed in the source material, limiting technical attribution and IOC extraction. The listing appears to be a standard ransomware-leak-site tracking entry rather than a detailed incident report, and should be treated as an indicator of a claimed compromise pending further validation.

Mentioned in this report

Threat actors chaos
Malware Chaos

Source reporting: https://www.ransomware.live/id/YWlyY3JlZWJlYy5jYUBjaGFvcw==

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free