AirIndia Data Breach

Article by Tsaaro

7 min read

AirIndia Data Breach

National carrier Air India has recently flagged a cyber attack on its servers and has notified its passengers of a data breach that had occurred in February at the SITA passenger service system. Air India’s leaked customer database exposed registered personal details of about 4.5 Million passengers. Data subjects included PIIs such as: name, date of birth, contact contact information, passport information, ticket information, Star Alliance frequent flyer data and credit card details. But Air India said neither CVV/CVC numbers associated with the credit cards nor passwords were affected. This is the second major airline data breach in the last six months after IndiGo got breached last December.

Supply Chain Breach: More about SITA   

SITA is a Switzerland-based technology company specialising in air transport communications and information technology. The company was started by 11 member airlines and now has over 2,500 customers in more than 200 countries, claiming to serve around 90% of the global airline business. SITA is the data processor of Air India’s Passenger Processing Service (PSS) and is responsible for storing and processing the personal information of its customers. Air India had entered into a deal with SITA in 2017 to upgrade its IT infrastructure to enable it to join Star Alliance. At Air India, SITA also implemented an online booking engine, departure control system, check-in and automated boarding control, baggage reconciliation system and the frequent flyer programme.

SITA disclosed it suffered a “highly sophisticated attack” on its servers located in Atlanta, leading to a compromise of passenger data stored in its PSS system. Although Air India had received the first notification in this regard from their data processor on 25.02.2021, however, the identity of the affected data subjects were disclosed by their data processor on 25.03.2021 and 5.04.2021. Air India said no subsequent unauthorised activity had been detected.

Air India: Incident Response

In modern IT Supply Chain attacks, there is a constant need to monitor the potential risks across a vast ecosystem that includes: vector-associated DNS management, cloud providers, web properties, encryption, certificates and mobile infrastructures. Unfortunately, the modern IT organization is not prepared to monitor, let alone manage a risk of such high severity. Hackers and malicious actors can easily penetrate through the defense mechanisms placed in such environments, making them extremely vulnerable. When there is a lack of clearly defined oversight and management processes, hackers are able to operate freely and inflict significantly more damage.

Following the incident, Air India said it took a number of steps to investigate the key elements of the sophisticated attack and remediate the issue. These include:

  • Securing the compromised servers
  • Engaging external data security specialists
  • Contacting the credit card issuers and advising them to reset the passwords of Air India frequent flyer programmes
  • Emailing it’s customers to inform them about the severity of the data breach.

While Air India assured its passengers that there was no evidence of any “misuse” of the data, it said it was in talks with regulatory agencies in India and overseas and also advised the passengers to change their passwords wherever applicable to thwart potential unauthorized attempts and ensure the safety of their personal data.

Conclusion

With the latest development, Air India joins a long list of airlines, such as Lufthansa, Cathay Pacific, Air New Zealand, Singapore Airlines, Scandinavian Airlines (SAS), Finnair, Malaysia Airlines, South Korea’s Jeju Air, American Airlines, and United Airlines that have been impacted by data security incidents in the past.

For more information, you can contact: email id aidata.helpdesk@airindia.in, or call on 01242641415 or visit the website www.airindia.in, Air India said in its communique to the affected passengers. Air India is only operating domestic flights as international travel remains suspended owing to the coronavirus disease (Covid-19) pandemic.

67 thoughts on “AirIndia Data Breach”

  1. Can I simply say what a comfort to discover a person that actually knows what they are talking about online. You actually realize how to bring a problem to light and make it important. More and more people ought to check this out and understand this side of your story. I can’t believe you’re not more popular given that you most certainly have the gift.

  2. Having read this I thought it was rather informative. I appreciate you taking the time and effort to put this content together. I once again find myself spending a lot of time both reading and commenting. But so what, it was still worthwhile.

  3. An impressive share! I have just forwarded this onto a friend who was conducting a little homework on this. And he in fact ordered me lunch because I stumbled upon it for him… lol. So allow me to reword this…. Thanks for the meal!! But yeah, thanks for spending time to discuss this issue here on your internet site.

  4. I’m impressed, I have to admit. Seldom do I come across a blog that’s both educative and interesting, and without a doubt, you have hit the nail on the head. The issue is something that not enough folks are speaking intelligently about. I am very happy I found this in my search for something concerning this.

  5. На нашем сайте представлены свежие промокоды для Lamoda. Примените их, чтобы получить выгодную покупку на топовые товары. Коды на скидку обновляются каждую неделю, чтобы вы всегда могли воспользоваться лучшими предложениями.
    Ламода скидка по купону

  6. На нашем сайте вы можете найти брендовые сумки Bottega Veneta. Здесь можно приобрести актуальные модели, которые добавят элегантности вашему образу. Каждая сумка характеризуется безупречной отделкой, что свойственно бренду этой марки
    https://gorillasocialwork.com/story19525693/bottega-veneta

  7. Hello there! I simply wish to offer you a big thumbs up for the excellent information you’ve got right here on this post. I’ll be returning to your website for more soon.

  8. Greetings, I do think your web site could be having internet browser compatibility problems. When I take a look at your site in Safari, it looks fine however when opening in I.E., it has some overlapping issues. I merely wanted to provide you with a quick heads up! Other than that, wonderful website.

  9. Oh my goodness! Incredible article dude! Thank you, However I am having difficulties with your RSS. I don’t know the reason why I am unable to join it. Is there anyone else having the same RSS problems? Anyone who knows the solution can you kindly respond? Thanks.

  10. Hi there! Do you know if they make any plugins to help
    with SEO? I’m trying to get my site to rank for some targeted keywords
    but I’m not seeing very good success. If you
    know of any please share. Thank you! I saw similar article here:
    Warm blankets

  11. Hi, I believe your web site could be having browser compatibility issues. When I look at your blog in Safari, it looks fine however, if opening in Internet Explorer, it’s got some overlapping issues. I simply wanted to give you a quick heads up! Besides that, excellent blog.

  12. I have to thank you for the efforts you’ve put in writing this blog. I’m hoping to view the same high-grade blog posts by you in the future as well. In truth, your creative writing abilities has inspired me to get my own, personal blog now 😉

  13. An outstanding share! I have just forwarded this onto a colleague who has been conducting a little research on this. And he actually bought me lunch due to the fact that I found it for him… lol. So allow me to reword this…. Thanks for the meal!! But yeah, thanx for spending some time to discuss this topic here on your blog.

  14. Right here is the right web site for anyone who really wants to find out about this topic. You know so much its almost tough to argue with you (not that I actually will need to…HaHa). You certainly put a brand new spin on a subject which has been discussed for ages. Excellent stuff, just great.

  15. You’re so cool! I don’t think I’ve truly read through something like that before. So wonderful to discover another person with unique thoughts on this subject matter. Seriously.. thanks for starting this up. This web site is something that is required on the web, someone with a bit of originality.

  16. Hi, I do believe this is an excellent site. I stumbledupon it 😉 I will come back yet again since i have bookmarked it. Money and freedom is the best way to change, may you be rich and continue to guide other people.

Leave a Reply

Your email address will not be published. Required fields are marked *

Shubham Bansal

INTRODUCTION: The Personal Data Protection Law No. 6698, known as Kişisel Verileri Koruma Kanunu (KVKK), is Türkiye’s landmark data protection …

Tsaaro Consulting

At the Singapore International Cyber Week 2024, The Cyber Security Agency (CSA) of Singapore released Guidelines on Securing Artificial Intelligence …

Tsaaro Consulting

The European Data Protection Board (EDPB) on 8th October 2024, issued draft Guidelines 1/2024 on processing of personal data based …

Tsaaro Consulting

Introduction   With data playing a pivotal role in business operations, ensuring data privacy compliance has become a key focus in …

Tsaaro Consulting

The FinTech industry has transformed the financial landscape, offering customers digital solutions that make banking, lending, insurance, and investing more …

Recent Comments

SHARE THIS POST

Would you like to read regular updates from Tsaaro.
Subscribe to our newsletter

Our Latest Blogs

Read what the latest hapennings in the cyber world are and learn what the
experts have to say about them