SITA says its airline passenger system was hit by a data breach

Global air transport data giant SITA has confirmed a data breach involving passenger data.

The company said in a brief statement on Thursday that it had been the “victim of a cyberattack,” and that certain passenger data stored on its U.S. servers had been breached. The cyberattack was confirmed on February 24, after which the company contacted affected airlines. SITA is one of the largest aviation IT companies in the world, said to be serving around 90% of the world’s airlines, which rely on the company’s passenger service system Horizon to manage reservations, ticketing, and aircraft departures. But it remains unclear exactly what data was accessed or stolen. When reached, SITA spokesperson Edna Ayme-Yahil declined to say what specific data had been taken, citing an ongoing investigation. The company said that the incident “affects various airlines around the world, not just in the United States.” SITA confirmed it had notified several airlines — Malaysia Airlines; Finnair; Singapore Airlines; and Jeju Air, an airline in South Korea — which have already made statements about the breach, but declined to name other affected airlines. In an email to affected customers seen by TechCrunch, Singapore Airlines said it was not a customer of SITA’s Horizon passenger service system but that about half a million frequent flyer members had their membership number and tier status compromised. The airline said that the transfer of this kind of data is “necessary to enable verification of the membership tier status, and to accord to member airlines’ customers the relevant benefits while traveling.” The airline said passenger itineraries, reservations, ticketing, and passport data were not affected. SITA is one of a handful of companies in the aviation market providing passenger ticketing and reservation systems to airlines, alongside Sabre and Amadeus. Sabre reported a major data breach in mid-2017 affecting its hotel reservation system, after hackers scraped over a million customer credit cards. The U.S.-based company agreed in December to a $2.4 million settlement and to make changes to its cybersecurity policies following the breach. In 2019, a security researcher found a vulnerability in Amadeus’ passenger booking system, used by Air France, British Airways, and Qantas among others, which made it easy to alter or access traveler records.

Early Stage is the premier ‘how-to’ event for startup entrepreneurs and investors. You’ll hear first-hand how some of the most successful founders and VCs build their businesses, raise money and manage their portfolios. We’ll cover every aspect of company-building: Fundraising, recruiting, sales, product market fit, PR, marketing and brand building. Each session also has audience participation built-in – there’s ample time included for audience questions and discussion.

<iframe
        id="wpcom-iframe-dde292b93a5f3017145419dd51bb9fce"
        width="99%"
        height="1500"
        src="https://tcprotectedembed.com/protected-iframe/dde292b93a5f3017145419dd51bb9fce"
        scrolling="true"
        frameborder="0"
        class="wpcom-protected-iframe"
>
</iframe>
<script type="text/javascript">
    ( function() {
        var func = function() {
            var iframe = document.getElementById('wpcom-iframe-dde292b93a5f3017145419dd51bb9fce')
            if ( iframe ) {
                iframe.onload = function() {
                    iframe.contentWindow.postMessage( {
                        'msg_type': 'poll_size',
                        'frame_id': 'wpcom-iframe-dde292b93a5f3017145419dd51bb9fce'
                    }, "https:\/\/tcprotectedembed.com" );
                }
            }

            // Autosize iframe
            var funcSizeResponse = function( e ) {

                var origin = document.createElement( 'a' );
                origin.href = e.origin;

                // Verify message origin
                if ( 'tcprotectedembed.com' !== origin.host )
                    return;

                // Verify message is in a format we expect
                if ( 'object' !== typeof e.data || undefined === e.data.msg_type )
                    return;

                switch ( e.data.msg_type ) {
                    case 'poll_size:response':
                        var iframe = document.getElementById( e.data._request.frame_id );

                        if ( iframe && '' === iframe.width )
                            iframe.width = '100%';
                        if ( iframe && '' === iframe.height )
                            iframe.height = parseInt( e.data.height );

                        return;
                    default:
                        return;
                }
            }

            if ( 'function' === typeof window.addEventListener ) {
                window.addEventListener( 'message', funcSizeResponse, false );
            } else if ( 'function' === typeof window.attachEvent ) {
                window.attachEvent( 'onmessage', funcSizeResponse );
            }
        }
        if (document.readyState === 'complete') { func.apply(); /* compat for infinite scroll */ }
        else if ( document.addEventListener ) { document.addEventListener( 'DOMContentLoaded', func, false ); }
        else if ( document.attachEvent ) { document.attachEvent( 'onreadystatechange', func ); }
    } )();
</script>

Leave a Reply