Air Côte d’Ivoire confirms February 8 system breach after INC claim

THE BRIEF
Air Côte d’Ivoire has confirmed that hackers breached its systems on February 8, according to a statement reported by The Record from Recorded Future News. The airline’s confirmation followed a claim by the INC ransomware gang that it had stolen 208 GB of data. The report says Air Côte d’Ivoire did not respond to requests for comment but later issued the Friday statement confirming reports of the breach. The available account does not establish whether the gang’s data claim was independently verified, what systems were affected, whether data was published, or whether operations were disrupted. It also does not provide details about the intrusion method, the information allegedly taken, or the identity of the attackers beyond the group’s own claim. Organizations reviewing the report should distinguish the airline’s confirmation that its systems were breached from the separate ransomware group assertion about the volume of data allegedly stolen.
WHY IT MATTERS
The report separates two important claims: Air Côte d’Ivoire confirmed a systems breach, while INC claimed responsibility and alleged that 208 GB of data was stolen. Those assertions should not be treated as equivalent evidence. Until further information is available, the scope, affected information, operational impact, and publication status remain unclear. The incident is relevant to organizations that depend on continuously available systems or hold sensitive business and customer information, particularly when evaluating incident-response readiness and communications around ransomware allegations.
WHO SHOULD CARE
Airlines, transportation organizations, security leaders, privacy teams, incident responders, and legal advisers should monitor developments and prepare to assess possible data exposure without assuming that the ransomware group’s claim has been verified.
WHAT TO DO NOW
- Review incident records and determine which systems and information, if any, were affected by the confirmed breach.
- Preserve relevant logs, endpoint data, and communications so the organization can assess the incident and respond to follow-up questions.
- Evaluate whether the available facts trigger notification, reporting, or other obligations under applicable requirements.
- Brief leadership and relevant stakeholders using separate language for the confirmed breach and INC’s unverified data-theft claim.