# Chaos ransomware lists Air Creebec as victim

Published: 2026-07-06 · Severity: medium · Sectors: transportation
Canonical: https://vorant.io/reports/f0c80bb5-9016-53af-b3c0-35da5e5162e1/chaos-ransomware-lists-air-creebec-as-victim

> Ransomware.live shows Quebec airline Air Creebec listed as a victim by the Chaos ransomware operation, exposing thousands of user records.

A listing on Ransomware.live identifies aircreebec.ca, the domain of Quebec-based regional carrier Air Creebec, as a victim of the Chaos ransomware group. The entry reports a small number of directly compromised employee accounts alongside a much larger pool of nearly 9,700 compromised user credentials and seven third-party employee credentials, suggesting the exposure may stem partly from infostealer-derived credential leakage rather than a single breach event.

No file hashes, C2 infrastructure, or exploited vulnerabilities are disclosed in the source material, limiting technical attribution and IOC extraction. The listing appears to be a standard ransomware-leak-site tracking entry rather than a detailed incident report, and should be treated as an indicator of a claimed compromise pending further validation.

## Mentioned in this report

- Threat actors: chaos
- Malware: Chaos

Source reporting: https://www.ransomware.live/id/YWlyY3JlZWJlYy5jYUBjaGFvcw==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f0c80bb5-9016-53af-b3c0-35da5e5162e1/chaos-ransomware-lists-air-creebec-as-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
