Stay Safe - Hackers are Targeting Airlines for Lucrative InformationsteemCreated with Sketch.

in #security5 years ago

Hello Steemians! About one and a half months ago, British Airways were reportedly hacked. At that point, it was said that about 380,000 passengers' information was breached. However, last week, new statements were released that potentially, more information were breached than the original estimation. Also in the past week, Cathay Pacific released a statement informing their customers that they had been hacked. In this hack, a massive 9.4 million passengers information were breached.

Let us take a closer look into these 2 incidents and understand the impact and potential learning points.


British Airways Hack

image.png

How many customers were affected?

  • At least 380,000 passengers were affected and British Airways recent statements are saying that there could be more

What information were breached?

  • Credit card information
  • Personal information like passengers' names and home addresses

How did the hack happen?

  • Through a web-based vulnerability known as cross-site scripting. Users were redirected to a fraudulent site due to this vulnerability and information were forwarded to the hackers' servers as part of a legitimate transaction on British Airways website

What are the impacts on the company?

  • Share price tanked following the hack. Source.
  • Reputational impact
  • Will possibly be fined by regulators and government

How do I know if I am affected? And what should I do if I am?

  • British Airways put up a page to provide all the information you need to determine if you are affected and what should you do if you are

Cathay Pacific Hack

image.png

How many customers were affected?

  • 9.4 million passengers were affected

What information were breached?

  • Personal information such as, names of passengers, their nationalities, dates of birth, telephone numbers, email and physical addresses, passport numbers, identity card numbers
  • Credit card information

How did the hack happen?

  • Information is still scarce but security experts believe it to be vulnerabilities in Cathay Pacific cloud infrastructure. Source.
  • Poor cloud security hygiene could have led to direct access to Cathay Pacific's databases in the cloud.

What are the impacts on the company?

  • Share price tanked following the hack. Source.
  • Reputational impact
  • Will possibly be fined by regulators and government

How do I know if I am affected? And what should I do if I am?

  • Cathay Pacific put up a page to provide all the information you need to determine if you are affected and what should you do if you are

Learning Points and Conclusion

As companies start to embark in technology refresh/change to their infrastructure, it is always important to have security in mind. I have seen many cases where technology moves without considering security and resulted in unnecessary risks. Furthermore, these 2 incidents also highlighted that the detection mechanism of hacks and breaches is key to any companies. As a cybersecurity practitioner, we all understand that it is impossible to secure your perimeters to ensure zero vulnerabilities. What is important is rather the detection mechanism and the incident response process. We will need to assume that breach is going to happen and be prepared for one when it does happen.

Through these 2 incidents, we can also see that hackers are always looking for the path of least resistance. Unlike banks, airlines are not that heavily regulated and hence, their security posture may not be as good. However, lucrative information are still held by these companies and they may be seen as easier targets by hackers.

Thanks for reading! Let me know your thoughts on these 2 recent security incidents. Are you affected by any of them? If you like what you have read, do give me an upvote and a follow.

steem-divider1.png

Projects/Services I am working on:


You can find me in these communities:

Sort:  

hi @culgin

What an interesting post. I wonder when will all those companies change their approach to security and will pay more interest to blockchain (as a solution)

I olny wanted to thank you again for your support and valuable comment regarding my latest Trivial review.

Just figured that I will drop by and leave an upvote as a small token of appreciation.

have a great sunday,
Piotr

Thanks @crypto.piotr!

Posted using Partiko Android

hi @culgin

I dropped by to thank you for your constant support and great recent comments.
Just a quick note: I will be away for a couple of days (Im getting married very soon) and I only

I would really love to be able to keep in touch with you via email (Im not much into chating apps and Steemit doesnt have any messaging system).

My email: [email protected]

Perhaps you would like to reach out to me one day. I value your work here on Steemit a lot and I believe that people like us should stick together.

Yours
Piotr

Hi @crypto.piotr, I have responded to you via email. Let's continue our conversation over there. Congratulations on your wedding!

Posted using Partiko Android

Lovely :)

Thx for your kind wishes @culgin

Oh shit! There are more and more big hacks these days...
Well explained as usual @clugin, resteemed!

Indeed. There are many high profile hacks these days and for many organizations, it is really a not a matter of "if" but "when".

Thanks for the support my friend!

Posted using Partiko Android

Indeed. There are many high profile hacks these days and for many organizations, it is really a not a matter of "if" but "when".

Thanks for the support my friend!

Posted using Partiko Android

Hi @culgin!

Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your UA account score is currently 3.110 which ranks you at #9466 across all Steem accounts.
Your rank has improved 8 places in the last three days (old rank 9474).

In our last Algorithmic Curation Round, consisting of 230 contributions, your post is ranked at #90.

Evaluation of your UA score:
  • You're on the right track, try to gather more followers.
  • The readers appreciate your great work!
  • You have already shown user engagement, try to improve it further.

Feel free to join our @steem-ua Discord server

YOU JUST GOT UPVOTED

Congratulations,
you just received a 13.59% upvote from @steemhq - Community Bot!

Wanna join and receive free upvotes yourself?
Vote for steemhq.witness on Steemit or directly on SteemConnect and join the Community Witness.

This service was brought to you by SteemHQ.com

Coin Marketplace

STEEM 0.32
TRX 0.12
JST 0.034
BTC 64664.11
ETH 3166.18
USDT 1.00
SBD 4.11