Passport details potentially lifted from Air Canada app

Airline said it has contacted customers about the data breach

AirCanada plane taking off

Air Canada has issued a warning on its website that its app has suffered a data breach that may have resulted in the theft of thousands of its customer's personal data.

The airline has undertaken an investigation into "unusual" login behaviour on its app, which has approximately 1.7 million users of which 1% or 20,000 profiles may potentially have been improperly accessed.

Advertisement - Article continues below

"We detected unusual login behaviour with Air Canada's mobile App between Aug 22 and 24, 2018," a spokesperson said on the company's website. "We immediately took action to block these attempts and implemented additional protocols to protect against further unauthorized attempts."

The airline said customer privacy and the protection of their data is extremely important. It stressed that it has multi-layered security and that it works with leading industry experts to continuously improve company practices with technology and security procedures.

According to the website warning, all credit card information is protected by encryption, but customers are being advised to monitor credit card transactions and contact financial services providers immediately if they become aware of any unusual or unauthorised activities.

As an additional security precaution, all Air Canada mobile app accounts have been locked to protect customers data, but potentially many of its users' basic profile data could have been taken, including names, email addresses and telephone numbers. There is also a worry that extra information added by users has also been accessed, such as passport details.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Airline apps are generally a lot smarter than they used to be, with the boarding pass, video playback and payment functionality being added to the usual frequent flyer points display. And all of those advanced features have to work on a plane, which is largely an offline environment, where network-based security tools won't help.

"The security models for many airline apps haven't evolved along with the user features," said Winston Bond, senior technical director EMEA at Arxan Technologies.

"We would expect to see the strong level of app protection that gets applied to mobile wallet apps and commercial video playback apps, but airline apps are still not being obfuscated and they still store all the offline data in unencrypted databases. It isn't hard for an attacker to reverse engineer these apps and work out how to extract all the user data."

This is the latest data breach resulting from a company app, last month social media app Timehop became the victim of a "network intrusion" that affected some 21 million of its users because it didn't have multi-factor authentication.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020
Visit/business-strategy/mergers-and-acquisitions/354941/panda-security-to-be-acquired-by-watchguard
mergers and acquisitions

Panda Security to be acquired by WatchGuard

9 Mar 2020
Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/infrastructure/server-storage/355118/hpe-warns-of-critical-bug-that-destroys-ssds-after-40000-hours
Server & storage

HPE warns of 'critical' bug that destroys SSDs after 40,000 hours

26 Mar 2020
Visit/software/video-conferencing/355138/zoom-beaming-ios-user-data-to-facebook-for-targeted-ads
video conferencing

Zoom beams iOS user data to Facebook for targeted ads

27 Mar 2020
Visit/software/355113/companies-offering-free-software-to-fight-covid-19
Software

These are the companies offering free software during the coronavirus crisis

25 Mar 2020
Visit/mobile/mobile-phones/355088/apple-lifts-iphone-purchase-restrictions
Mobile Phones

Apple lifts iPhone purchase restrictions

23 Mar 2020