AirIndia Data Breach

National carrier Air India has recently flagged a cyber attack on its servers and has notified its passengers of a data breach that had occurred in February at the SITA passenger service system. Air India’s leaked customer database exposed registered personal details of about 4.5 Million passengers. Data subjects included PIIs such as: name, date of birth, contact contact information, passport information, ticket information, Star Alliance frequent flyer data and credit card details. But Air India said neither CVV/CVC numbers associated with the credit cards nor passwords were affected. This is the second major airline data breach in the last six months after IndiGo got breached last December.

Supply Chain Breach: More about SITA   

SITA is a Switzerland-based technology company specialising in air transport communications and information technology. The company was started by 11 member airlines and now has over 2,500 customers in more than 200 countries, claiming to serve around 90% of the global airline business. SITA is the data processor of Air India’s Passenger Processing Service (PSS) and is responsible for storing and processing the personal information of its customers. Air India had entered into a deal with SITA in 2017 to upgrade its IT infrastructure to enable it to join Star Alliance. At Air India, SITA also implemented an online booking engine, departure control system, check-in and automated boarding control, baggage reconciliation system and the frequent flyer programme.

SITA disclosed it suffered a “highly sophisticated attack” on its servers located in Atlanta, leading to a compromise of passenger data stored in its PSS system. Although Air India had received the first notification in this regard from their data processor on 25.02.2021, however, the identity of the affected data subjects were disclosed by their data processor on 25.03.2021 and 5.04.2021. Air India said no subsequent unauthorised activity had been detected.

Air India: Incident Response

In modern IT Supply Chain attacks, there is a constant need to monitor the potential risks across a vast ecosystem that includes: vector-associated DNS management, cloud providers, web properties, encryption, certificates and mobile infrastructures. Unfortunately, the modern IT organization is not prepared to monitor, let alone manage a risk of such high severity. Hackers and malicious actors can easily penetrate through the defense mechanisms placed in such environments, making them extremely vulnerable. When there is a lack of clearly defined oversight and management processes, hackers are able to operate freely and inflict significantly more damage.

Following the incident, Air India said it took a number of steps to investigate the key elements of the sophisticated attack and remediate the issue. These include:

  • Securing the compromised servers
  • Engaging external data security specialists
  • Contacting the credit card issuers and advising them to reset the passwords of Air India frequent flyer programmes
  • Emailing it’s customers to inform them about the severity of the data breach.

While Air India assured its passengers that there was no evidence of any “misuse” of the data, it said it was in talks with regulatory agencies in India and overseas and also advised the passengers to change their passwords wherever applicable to thwart potential unauthorized attempts and ensure the safety of their personal data.

Conclusion

With the latest development, Air India joins a long list of airlines, such as Lufthansa, Cathay Pacific, Air New Zealand, Singapore Airlines, Scandinavian Airlines (SAS), Finnair, Malaysia Airlines, South Korea’s Jeju Air, American Airlines, and United Airlines that have been impacted by data security incidents in the past.

For more information, you can contact: email id aidata.helpdesk@airindia.in, or call on 01242641415 or visit the website www.airindia.in, Air India said in its communique to the affected passengers. Air India is only operating domestic flights as international travel remains suspended owing to the coronavirus disease (Covid-19) pandemic.

53 thoughts on “AirIndia Data Breach”

  1. helloI really like your writing so a lot share we keep up a correspondence extra approximately your post on AOL I need an expert in this house to unravel my problem May be that is you Taking a look ahead to see you

  2. obviously like your website but you need to test the spelling on quite a few of your posts Several of them are rife with spelling problems and I to find it very troublesome to inform the reality on the other hand Ill certainly come back again

  3. My brother suggested I might like this blog He was totally right This post actually made my day You can not imagine simply how much time I had spent for this info Thanks

  4. Your blog is a treasure trove of valuable insights and thought-provoking commentary. Your dedication to your craft is evident in every word you write. Keep up the fantastic work!

  5. I share your level of appreciation for the work you’ve produced. The sketch you’ve displayed is elegant, and the content you’ve authored is sophisticated. Yet, you appear to be concerned about the possibility of heading in a direction that could be seen as dubious. I agree that you’ll be able to resolve this matter efficiently.

  6. Nice blog here Also your site loads up fast What host are you using Can I get your affiliate link to your host I wish my web site loaded up as quickly as yours lol

  7. You did an excellent job of producing an intricate, beautiful, and well-written piece of work. The presentation is aesthetically pleasing, and the written composition is sophisticated. However, it appears that you are concerned about the possibility of presenting something that is deemed to be suspicious. Yes, I anticipate that you will be able to address this problem immediately.

  8. Hello Neat post Theres an issue together with your site in internet explorer would check this IE still is the marketplace chief and a large element of other folks will leave out your magnificent writing due to this problem

  9. I loved as much as you will receive carried out right here The sketch is tasteful your authored subject matter stylish nonetheless you command get got an edginess over that you wish be delivering the following unwell unquestionably come further formerly again as exactly the same nearly very often inside case you shield this hike

  10. I have been browsing online more than three hours today yet I never found any interesting article like yours It is pretty worth enough for me In my view if all website owners and bloggers made good content as you did the internet will be a lot more useful than ever before

  11. What i dont understood is in reality how youre now not really a lot more smartlyfavored than you might be now Youre very intelligent You understand therefore significantly in terms of this topic produced me personally believe it from a lot of numerous angles Its like women and men are not interested except it is one thing to accomplish with Woman gaga Your own stuffs outstanding Always care for it up

  12. I have been surfing online more than 3 hours today yet I never found any interesting article like yours It is pretty worth enough for me In my opinion if all web owners and bloggers made good content as you did the web will be much more useful than ever before

  13. What i dont understood is in reality how youre now not really a lot more smartlyfavored than you might be now Youre very intelligent You understand therefore significantly in terms of this topic produced me personally believe it from a lot of numerous angles Its like women and men are not interested except it is one thing to accomplish with Woman gaga Your own stuffs outstanding Always care for it up

  14. Профессиональный сервисный центр по ремонту сотовых телефонов, смартфонов и мобильных устройств.
    Мы предлагаем: где можно починить телефон
    Наши мастера оперативно устранят неисправности вашего устройства в сервисе или с выездом на дом!

  15. Профессиональный сервисный центр по ремонту радиоуправляемых устройства – квадрокоптеры, дроны, беспилостники в том числе Apple iPad.
    Мы предлагаем: ремонт квадрокоптера
    Наши мастера оперативно устранят неисправности вашего устройства в сервисе или с выездом на дом!

  16. Профессиональный сервисный центр по ремонту бытовой техники с выездом на дом.
    Мы предлагаем:ремонт крупногабаритной техники в петрбурге
    Наши мастера оперативно устранят неисправности вашего устройства в сервисе или с выездом на дом!

  17. Профессиональный сервисный центр по ремонту варочных панелей и индукционных плит.
    Мы предлагаем: ремонт электрических варочных панелей на дому москва
    Наши мастера оперативно устранят неисправности вашего устройства в сервисе или с выездом на дом!

  18. Профессиональный сервисный центр по ремонту бытовой техники с выездом на дом.
    Мы предлагаем:сервисные центры по ремонту техники в екб
    Наши мастера оперативно устранят неисправности вашего устройства в сервисе или с выездом на дом!

Leave a Reply

Your email address will not be published. Required fields are marked *