
Denver-based ultra-low-cost carrier Frontier Airlines is facing two class action lawsuits, following two data breaches in May and June. The lawsuits were filed on July 15 at the United States District Court for the District of Colorado, and have accused the carrier of not protecting customer and employee data.
The data breach, carried out by a hacker supergroup, gained access to Social Security numbers, addresses, and government-issued ID numbers; these are just some of the personal data that were compromised. The two data breaches occurred on May 12 and June 3, 2026.
A Reasonable Level Of Security Would Have Prevented The Hack
According to the report by AL, Frontier is facing class action lawsuits due to insufficiently protecting the customer and employee data, and the claim suggests that the airline did not provide a reasonable level of security that could have prevented the hacking from occurring. Frontier, however, has been suggested to have focused on increasing its profits instead of implementing effective security measures. As reported in TopClassActions, below is one of the statements for the lawsuit:
“Instead of providing a reasonable level of security that would have prevented the hacking incident, [Frontier] instead calculated to increase its own profits at the expense of plaintiff and class members by utilizing cheaper, ineffective security measures.”
Frontier has also been claimed to have not notified those who were impacted by the breach until last month, with the lawsuit now also suggesting that the airline kept this information from victims, which therefore meant the individuals affected were unable to protect themselves sooner. Frontier did not start notifying victims until July 9, whereas the airline became aware of the breach on June 18.
Victims of the Frontier Airlines Data Breach Remain Unknown
At this stage, it is unclear how many victims were affected, but AL details that there have been individuals who have been identified in the US states of Texas, Massachusetts and Vermont who have confirmed that their data was included in the breach.
The lawsuit against Frontier looks for financial compensation for the plaintiffs, alongside a group of class members. Frontier has been requested to pay for a minimum of three years’ worth of credit monitoring for each of the victims. Plaintiffs Grace Stean and Kimah Beach have proposed a nationwide class for all those whose data was compromised, and have demanded a jury trial and to seek damages and injunctive relief for the entire class.
Since the breach, Stean claims that victims have seen an increase in spam calls and additional monitoring of personal credit, which, according to Stean, is tied to the breach. Simple Flying reached out to Frontier for comment; however, an airline spokesperson could not immediately be reached.
Why Are Data Breaches Bad For Airlines?
When an airline faces a data breach and confidential information has been hacked, this can expose private passenger details. As a result, victims may see their personal data shared with malicious third parties. Hackers continually target airlines due to the large amount of personal data from travelers and staff, as well as financial data.
Airlines can face heavy fines should the local government identify that an airline has failed to protect user data, and carriers, if found guilty, could be forced to pay for customer credit monitoring and legal fees. During such instances, airlines can also face revenue loss due to a lack of trust following a breach that sees customers look to other airlines, leading to brand harm and lost trust.
In the recent breaches for Frontier, the hacker supergroup known as ‘Scattered Lapsus$ Hunters’ gained access to the personal data of both customers and staff members. Details of the group are in the table below, as analyzed by Panda Security:
Group: | Scattered Lapsus$ Hunters |
|---|---|
Also Known As: | SLH, Trinity of Chaos |
Formed By: | Scattered Spider, LAPSUS$, ShinyHunters |
Known For: | International cybercrime supergroup, extortion alliance |
Date Formed: | Mid 2025 |
Known Tactics And Methods: | Social engineering, MFA Exploitation, Extortion-as-a-Service |
Known Campaigns: | Salesforce data breach, Frontier data breach |
It is suggested that the carrier knowingly did not notify the affected victims until weeks after the incident occurred, and when it became apparent to the airline, a lack of communication led to the potential exposure of personal information and delay in necessary monitoring. The airline will face the United States District Court in the District of Colorado and be required to plead its case.







