Star Alliance passenger data stolen in SITA data breach

The tails of various passenger aircrafts including Star Alliance and Lufthansa planes

Air transport IT supplier SITA has said that hundreds of thousands of passengers have had their data stolen following a cyber attack on its systems.

SITA, which services roughly 90% of the airline industry, announced on Thursday that it suffered a data breach on 24 February involving a portion of passenger data stored on its servers. The compromised servers in question operate passenger processing systems on behalf of airlines including those comprising the Star Alliance group.

SITA describes itself as the world’s leading specialist in air transport IT and communications and supplies hundreds of customers including Star Alliance, the world’s largest airline group. Prominent airlines that fall under the Star Alliance umbrella include United Airlines, Lufthansa, Thai Airways, and Air New Zealand, among 22 others.

The IT supplier said it briefed its customers and partners after mitigating the attack, and asked the airline group to inform their own customers that their data was stolen. Air New Zealand passengers, for example, were told in an email that their data was accessed, including details such as their name, frequent flier tier status, and membership number.

“We recognize that the COVID-19 pandemic has raised concerns about security threats, and, at the same time, cyber-criminals have become more sophisticated and active,” SITA said in a statement. “This was a highly sophisticated attack.

“SITA acted swiftly and initiated targeted containment measures. The matter remains under continued investigation by SITA’s Security Incident Response Team with the support of leading external experts in cyber-security.”

Like the OneWorld group, Star Alliance shares data between its member airlines to ensure passengers can enjoy perks and benefits between the partnering airlines. It’s unclear how many passengers from its 26 members were affected, or whether the hack compromised the data of all passengers from all airlines.

The Guardian has claimed that SITA informed Malaysia Airlines, Singapore Airlines, Finnair, and Jeju Air based in South Korea that their passengers had been affected by the breach, alongside the reports of Air New Zealand passengers being hit.

Keumars Afifi-Sabet
Features Editor

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.