WestJet confirmed a data theft affecting approximately 5,164,000 Canadian employees and customers, according to a July 2026 letter from the Office of the Privacy Commissioner of Canada (OPC). The information involved varied by person: some records may have included identity, contact, travel or government-identifier details. The OPC says credit and debit card numbers, expiry dates, CVVs, guest passwords and Social Insurance Numbers were not obtained.
What happened in the WestJet breach?
The incident occurred on June 12, 2025, according to the OPC’s July 2026 compliance letter. WestJet says it identified suspicious activity on June 13. The OPC says the airline discovered the breach on June 13 and reported it to the privacy commissioner on June 14, 2025.
In the OPC’s account, an unauthorized actor used social-engineering tactics and an employee’s personal information to access an employee account with administrative privileges and bypass multi-factor authentication (MFA). The actor moved through WestJet systems, deployed ransomware, took control of virtual servers, and accessed and copied data from cloud storage. The sources do not identify a threat group.
WestJet said in its incident update: “At no point was the safety and integrity of our airline operations in question.” That is the company’s statement about its operations.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
How many people were affected, and what information was involved?
The OPC puts the number of affected Canadian WestJet employees and customers at approximately 5,164,000. That is an overall estimate, not a statement that every person had the same information exposed.
| Information category | What the OPC says may have been involved |
|---|---|
| Identity and contact details | Names, dates of birth, email and mailing addresses, phone numbers, and gender. These categories may apply to some people, not everyone. |
| Travel information | Information about recent travel bookings may have been involved for some individuals. |
| Government identifiers | Passport information and other government-issued identifiers may have been involved for some individuals. |
| Payment details and credentials | The OPC says credit or debit card numbers, expiry dates, CVV numbers, and guest passwords were not obtained. |
| Social Insurance Numbers | The OPC says Social Insurance Numbers were not obtained. |
WestJet’s September 29, 2025 update said it was not aware of the relevant data being misused for identity theft or fraud at that time. That dated statement is not a guarantee that misuse could never occur.
How to check whether your information was involved
If WestJet sent you a direct email or letter, use that notice to find out which types of your information may have been involved and whether you are eligible for a protection service. WestJet says Cyberscout, a TransUnion division, was authorized to contact individuals on its behalf.
If you were not contacted but want to check, use the phone number or email listed on WestJet’s official incident FAQ. Verify unexpected calls, texts or emails through that page or a contact route you already know; do not rely on an unsolicited message to establish that it is genuine.
What should affected customers do?
- Check your travel details. WestJet recommends confirming flight information before you travel.
- Be alert for impersonation attempts. Watch for phishing emails, fraudulent calls and texts, and verify a caller’s identity before sharing personal information. WestJet says it does not email asking customers to provide payment-card information.
- Review financial accounts and credit files. Look for unusual activity on bank statements and credit reports, and contact your bank or card issuer promptly if you find something suspicious.
- Use protection services only as described in your notice. The OPC says WestJet offered affected individuals a 24-month subscription to credit monitoring and identity-theft protection. Eligibility and access instructions were provided in individual notices; this is not an open sign-up offer.
For affected minors, the OPC says parents and guardians were told about a High-Risk Fraud Alert database because minors are not eligible for the credit-monitoring service. The OPC also clarifies that Social Insurance Numbers were not impacted; monitoring a minor’s SIN was described as a harm-mitigation practice.
Were WestJet points or passwords affected?
WestJet’s incident FAQ says guest passwords were not affected and that the airline had no indication that points or point systems were at risk. It also says rewards functionality remained available. These are WestJet’s statements about its systems, not an independent guarantee about every account.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What has WestJet done, and what is the OPC reviewing?
WestJet says containment is complete and that it has implemented additional system and data-security measures. The OPC’s July 2026 compliance letter describes security changes including stronger MFA for employee and contractor accounts, moving away from less secure methods toward options such as authentication apps and hardware-based keys.
The OPC opened a Commissioner-initiated investigation on August 5, 2025, into the safeguards WestJet had in place and the adequacy of its notifications under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). In the compliance letter, signed July 8 and modified July 14, 2026, the OPC says WestJet accepted commitments to provide a confidential summary of an independent external security assessment by August 7, 2026, and information about recommendations by September 7, 2026. The Commissioner said the office would review the recommendations and their implementation, and could discontinue, continue or expand the investigation.
Best Value
The available published information does not establish whether WestJet met those deadlines or whether the investigation has since been discontinued, continued or expanded. The compliance letter is not a finding that WestJet violated PIPEDA: it expressly says it is neither an admission of liability or wrongdoing by WestJet nor a finding by the Commissioner of a contravention.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




