Air India cyber attack exposes 4.5m customers’ data
Breach involved personal data registered over a 10-year period including credit card, passport and date of birth information
24 May 2021 | 0
Air India has stated that a cyber attack three months ago on the systems of its data processor, SITA, has affected around 4.5 million of its customers around the world.
The breach involved personal data registered over a ten year period, between 26 August 2011 and 3 February 2021. The details exposed include name, date of birth, contact information, passport information, ticket information, Star Alliance and Air India frequent flyer data, and credit card data.
“However, in respect of this last type of data, CVV/CVC numbers are not held by our data processor,” the company stated in a release.
Air India first received news of the incident from SITA on 25 February, but only found out the identity of the affected data subjects on 25 March and 5 April. Following the breach, a number of steps were taken including securing the compromised servers and notifying and liaising with credit card issuers.
A spokesperson from SITA told IT Pro that its passenger processing services were the target of a “highly sophisticated but limited cyber attack” which affected passenger data stored on servers in SITA PSS’s data centre in Atlanta, Georgia.
“By global and industry standards, we identified this cyber attack extremely quickly. The matter remains under active investigation by SITA,” said the spokesperson.
The airline is encouraging its passengers to change passwords to ensure the safety of their personal data.
In February this year, SITA disclosed that hundreds of thousands of passengers had their data stolen following a cyber attack on its systems. The company suffered a data breach on 24 February involving a portion of passenger data stored on its servers, which operate passenger processing systems on behalf of airlines including those compromising the Star Alliance group.
© Dennis Publishing
Professional Development for IT professionals
The mission of the Irish Computer Society is to advance, promote and represent the interests of ICT professionals in Ireland. Membership of the ICS typically reduces courses by 20%. Find out more