Frontier Airlines is facing two proposed class actions after a data breach involving 11,482 employees and customers. A group calling itself Scattered Lapsus$ Hunters claimed it stole a “treasure trove” of personal information and demanded a ransom. The Texas Attorney General breach database is a primary public source for the headcount and timeline.
This is not a duplicate of our airline email-security listicle — that ranks domain scores. This post covers the 2026 breach, ransom claim, and July lawsuits.

Snapshot
| Field | Detail |
|---|---|
| Carrier | Frontier Airlines (flyfrontier.com) |
| Access window | May 12 – June 3, 2026 |
| Discovered | June 18, 2026 |
| People affected | 11,482 (Texas AG database) |
| Texas residents (Claim Depot) | 679 in notice summaries |
| Data types | Names, addresses, SSNs, DL / government IDs, DOBs, related PII |
| Threat claim | Scattered Lapsus$ Hunters — ransom demanded (not publicly confirmed paid) |
| Lawsuits | Two Colorado federal class actions ~Jul 15 (employee) and ~Jul 17 (passenger) |
What Frontier says it did
Frontier acknowledged the breach, hired an outside cybersecurity firm, contacted law enforcement, and says it found no evidence of continuing access. Plaintiffs allege notice letters arrived around July 9–14 — weeks after discovery — and argue cybersecurity and disclosure were inadequate under FTC-style standards.
Separately, a researcher flagged in March that confirmation number + last name could expose passenger data via Frontier’s site; Frontier said it fixed that specific issue. Whether it relates to this intrusion is unclear.
Why Texas travelers and employers should care
Texas is in the AG filing set. Anyone who flew Frontier or worked there and receives a letter should treat SSN / ID exposure as identity-theft fuel — and treat unsolicited “Frontier security claim” emails as phishing until verified on the official site.
Independent cybersecurity audits
Audited July 25, 2026. 100% is the ideal — none of these hosts reach it.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| Frontier Airlines | flyfrontier.com | 74% | 65% | 15% | 92% | −26 |
| BleepingComputer | bleepingcomputer.com | 63% | 75% | 15% | 40% | −37 |
| View from the Wing | viewfromthewing.com | 32% | 0% | 15% | 37% | −68 |
How to read this table: flyfrontier.com at 74% still has transport 15% — soft public mail-transport signals matter when passengers get spoofed breach-help email after lawsuits hit the news. Publisher domains are secondary sources only.
Audit links: flyfrontier.com · bleepingcomputer.com · viewfromthewing.com
Website stack note
Passive website-tech probe on July 25, 2026 for flyfrontier.com: no notable public CMS / PHP / short-horizon TLS flags. That does not speak to the May–June intrusion path or lawsuit merits. Point-in-time only.
What to do if you got a Frontier letter
- Enroll in any credit / identity monitoring in the notice.
- Consider a credit freeze if your SSN was in scope.
- Ignore unsolicited “claim portals” — use only contacts printed in the letter or on flyfrontier.com.
- Watch tax / unemployment fraud for 12–24 months.
Related
Run a free audit at audit.emailmenow.com or contact EmailMeNow for breach response and DMARC / MTA-STS work aimed at the 100% ideal.
Sources: View from the Wing — Frontier dual suits · Claim Depot — Frontier · Westword — Frontier lawsuits · Texas OAG breach portal