American Airlines disclosed in September 2022 that unauthorized access to a limited number of employee email accounts may have exposed personal information. The company said it discovered the activity on July 5, 2022, after reports that phishing emails had been sent from an employee account. This is a historical incident, not a new disclosure in 2026.
What happened in the American Airlines email incident?
American Airlines notified state regulators that unauthorized activity affected employee email accounts. The company said it learned of the activity after people reported phishing emails sent from an American employee’s account. It secured the affected accounts and brought in an outside cybersecurity forensic firm to investigate. The review included examining account contents to identify personal information that may have been present.
American’s disclosures describe a limited number of employee accounts. They do not establish that the airline’s full customer database or reservation system was breached. Contemporary reporting quoted the company describing the number of affected accounts as “very small,” but did not give a total count.
What personal information may have been exposed?
The information varied by person and could relate to an application for or employment with American, services provided to the company, or benefits received. The sample consumer notice lists these possible categories:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- Name, date of birth, mailing address, phone number, and email address
- Social Security number and employee number
- Driver’s license, passport, airman certification, or military identification number
- Certain medical information
This list describes information that could have been in an affected account; it does not mean every person’s information included every category. The disclosures do not say that payment-card information was involved.
How many people were affected?
American’s filing to the Maryland Office of the Attorney General estimated that approximately 37 Maryland residents may have been affected. That figure applies to Maryland only. The incident documents cited here do not establish a nationwide total.
What did American say about misuse and its response?
In its September 16, 2022 filing, American said it had no evidence that potentially affected Maryland residents’ information had been or would be misused. The sample consumer notice similarly said the company had no evidence of misuse. These were the company’s findings at the time of notice, not a guarantee that misuse could never occur later.
American said it secured the applicable accounts, retained an outside forensic firm, reviewed account contents, and added technical safeguards. Contemporary reporting said affected people were offered two years of identity protection through Experian. That offer was reported for affected individuals; check your own notice for eligibility and enrollment instructions rather than assuming it is available to all readers.
What should you do if you received a notice?
- Read the notice carefully. Confirm which information may have been involved and note any deadlines, contact details, or identity-protection enrollment instructions it gives.
- Verify any offer before enrolling. Use contact information in the notice or independently verified official American Airlines channels if you are unsure whether a communication is genuine.
- Take steps suited to the information listed. If the notice says a sensitive identifier may have been involved, monitor relevant financial or identity records and follow instructions from appropriate official sources. Do not assume that every listed category applies to you.
- Do not make unsupported changes. The incident disclosures do not say every customer needs to change a password, and they do not report payment-card exposure. Follow any account-specific guidance you receive.
How to handle a suspicious American Airlines email
American’s communication-security guidance says not to click links, open attachments, call phone numbers, or follow instructions in suspicious communications. It identifies warning signs including a message claiming there is a problem with an account or flight, a look-alike website link, an attachment, urgent demands, or an official-looking sender name paired with an unrelated email address.
American directs people to forward suspicious email to [email protected]. For current instructions, see the airline’s communication-security page.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




