What we know about the data breach targeting frequent flyer info


Load Error

A “highly sophisticated” cyber attack targeting frequent flyer data has affected at least 11 airlines around the globe, including U.S. carriers American and United. The Feb. 24 incident targeted SITA, a technology provider that helps process communications and passenger information across numerous carriers.

Fortunately for customers, the hackers were not successful in stealing critical information like customer passwords or credit card information, according to both SITA and the affected airlines. Instead, the breach appears to have been limited to data such as frequent flyer account numbers and status levels.

“We recognize that the COVID-19 pandemic has raised concerns about security threats, and, at the same time, cyber-criminals have become more sophisticated and active,” SITA said in a Friday statement acknowledging the incident, which it said “remains under continued investigation.”

Want more airline-specific news? Sign up for TPG’s free new biweekly Aviation newsletter!

“This was a highly sophisticated attack,” the company added.

Affected airlines also have begun reaching out to customers. Despite early reports that the breach may have affected only carriers of the Star Alliance frequent flyer group, other airlines have also been exposed.

In the U.S., both United and American had started emailing customers on Friday afternoon.

“It’s our understanding that the only information potentially accessed were customer names, MileagePlus numbers and Star Alliance statuses (Silver or Gold),” United said in an email to its members. “Importantly, no other personal information or passwords were exposed that would allow anyone to access your MileagePlus account.”

American sent out a similar email to customers.

Cyber secure: How to protect yourself against reward program data breaches

Neither are customers of SITA’s passenger service system, though their frequent-flyer information seems to have been exposed via partners that are. The system can, among other things, allow airlines to share tier status information with each other so that airlines can offer elite benefits to eligible customers of their partners.

At least nine other carriers were affected, according to media reports and emails sent by carriers. They include Cathay Pacific, Finnair, Japan Airlines, Jeju Air of Korea, Lufthansa, Malaysia Airlines, SAS and Singapore Airlines. Delta Air Lines told TPG that it had no indication it was exposed to the breach.

Still, Skift estimates that “more than two million travelers enrolled in the frequent flier programs (of the affected) airlines had some of their data hacked.”

While SITA and the airlines say no sensitive information was taken, some carriers suggested customers could change their passwords “out of an abundance of caution.”

Featured photo by Johner Images/Getty Images

SPONSORED: With states reopening, enjoying a meal from a restaurant no longer just means curbside pickup.

And when you do spend on dining, you should use a credit card that will maximize your rewards and potentially even score special discounts. Thanks to temporary card bonuses and changes due to coronavirus, you may even be able to score a meal at your favorite restaurant for free. 

These are the best credit cards for dining out, taking out, and ordering in to maximize every meal purchase.

Editorial Disclaimer: Opinions expressed here are the author’s alone, not those of any bank, credit card issuer, airlines or hotel chain, and have not been reviewed, approved or otherwise endorsed by any of these entities.

Source: Read Full Article