Air transport IT supplier SITA has said that hundreds of thousands of passengers have had their data stolen following a cyber attack on its systems.
SITA, which services roughly 90% of the airline industry, announced on Thursday that it suffered a data breach on 24 February involving a portion of passenger data stored on its servers. The compromised servers in question operate passenger processing systems on behalf of airlines including those comprising the Star Alliance group.
SITA describes itself as the world’s leading specialist in air transport IT and communications and supplies hundreds of customers including Star Alliance, the world’s largest airline group. Prominent airlines that fall under the Star Alliance umbrella include United Airlines, Lufthansa, Thai Airways, and Air New Zealand, among 22 others.
The IT supplier said it briefed its customers and partners after mitigating the attack, and asked the airline group to inform their own customers that their data was stolen. Air New Zealand passengers, for example, were told in an email that their data was accessed, including details such as their name, frequent flier tier status, and membership number.
“We recognize that the COVID-19 pandemic has raised concerns about security threats, and, at the same time, cyber-criminals have become more sophisticated and active,” SITA said in a statement. “This was a highly sophisticated attack.
Cost of a data breach report 2020
Find out what factors help mitigate breach costs
“SITA acted swiftly and initiated targeted containment measures. The matter remains under continued investigation by SITA’s Security Incident Response Team with the support of leading external experts in cyber-security.”
Like the OneWorld group, Star Alliance shares data between its member airlines to ensure passengers can enjoy perks and benefits between the partnering airlines. It’s unclear how many passengers from its 26 members were affected, or whether the hack compromised the data of all passengers from all airlines.
The Guardian has claimed that SITA informed Malaysia Airlines, Singapore Airlines, Finnair, and Jeju Air based in South Korea that their passengers had been affected by the breach, alongside the reports of Air New Zealand passengers being hit.
Remote workforce security report
Key challenges, security threats, and investment priorities of organisations during the pandemic
On-prem storage vs. public cloud storage
Economic advantages of on-premises object storage vs. public cloud for enterprise data storage
The future of CIAM
Four trends shaping identity and access management
Realising the benefits of automated machine learning
How to overcome machine learning obstacles and start reaping the benefits
See the original article here: ITPro