Air India cyber attack exposes 4.5 million customers’ data

The breach involved personal data registered over a ten year period including credit card, passport and date of birth information

Air India has stated that a cyber attack three months ago on the systems of its data processor, SITA, has affected around 4.5 million of its customers around the world.

The breach involved personal data registered over a ten year period, between 26 August 2011 and 3 February 2021. The details exposed include name, date of birth, contact information, passport information, ticket information, Star Alliance and Air India frequent flyer data, and credit card data.

“However, in respect of this last type of data, CVV/CVC numbers are not held by our data processor,” the company stated in a release.

Air India first received news of the incident from SITA on 25 February, but only found out the identity of the affected data subjects on 25 March and 5 April. Following the breach, a number of steps were taken including securing the compromised servers and notifying and liaising with credit card issuers.

A spokesperson from SITA told IT Pro that its passenger processing services were the target of a “highly sophisticated but limited cyber attack” which affected passenger data stored on servers in SITA PSS’s data centre in Atlanta, Georgia.

Related Resource

Defend your organisation from evolving ransomware attacks

Learn what it takes to reduce risk and strengthen operational resiliency

Defend your organisation from evolving ransomware attacks - whitepaper from VeritasDownload now

“By global and industry standards, we identified this cyber-attack extremely quickly. The matter remains under active investigation by SITA,” said the spokesperson.

The airline is encouraging its passengers to change passwords to ensure the safety of their personal data. 

In February this year, SITA disclosed that hundreds of thousands of passengers had their data stolen following a cyber attack on its systems. The company suffered a data breach on 24 February involving a portion of passenger data stored on its servers, which operate passenger processing systems on behalf of airlines including those compromising the Star Alliance group.

Featured Resources

Modern governance: The how-to guide

Equipping organisations with the right tools for business resilience

Free Download

Cloud operational excellence

Everything you need to know about optimising your cloud operations

Watch now

A buyer’s guide to board management software

Improve your board’s performance

The real world business value of Oracle autonomous data warehouse

Lead with a 417% five-year ROI

Download now

Recommended

Google Cloud to open new office in Pune, India
Cloud

Google Cloud to open new office in Pune, India

24 Jan 2022
China accused of hijacking Australian PM's WeChat account
social media

China accused of hijacking Australian PM's WeChat account

24 Jan 2022
Singapore and Madrid named biggest movers in latest data centre rankings
data centres

Singapore and Madrid named biggest movers in latest data centre rankings

20 Jan 2022
UK and Australia partner on cyber security investment
Policy & legislation

UK and Australia partner on cyber security investment

20 Jan 2022

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

6 Jan 2022
Dell XPS 15 (2021) review: The best just got better
Laptops

Dell XPS 15 (2021) review: The best just got better

14 Jan 2022
How to speed up Windows 11
Microsoft Windows

How to speed up Windows 11

7 Jan 2022