Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > British Airways | Executive Club
Reload this Page >

SITA [airline IT provider] data breach, some BAEC data compromised

Community
Wiki Posts
Search

SITA [airline IT provider] data breach, some BAEC data compromised

Thread Tools
 
Search this Thread
 
Old Mar 5, 2021, 11:55 am
  #46  
 
Join Date: Jun 2015
Location: LHR, LGW
Programs: BAEC
Posts: 3,440
Originally Posted by BETTERMJ
Have had the same experience as everybody above. Just called GGL line. Sounds like they're getting inundated with calls about this. I feel sorry for them having to deal with this at 6.30pm on a Friday night.
GGL line confirmed that my account is locked and on the phone we tried to unlock it with a new password after they sent me a reset link, but, as with others above, it is not recognising the BAEC number. So failed which GGL operator was not expecting. He confirmed it will go to another department to unlock.
So have decided to just leave it till Monday and let them sort it out. If the account is locked, and they have told me that, and they have confirmed my current balances in an email, then I am ok to wait while they get themselves sorted.
Good plan. I would urge anyone reading this to give them time to fix whatever is broken. Just note whatever is held in your account as a just in case. But I’m sure it will be fixed if they’ve triggered that email.
BETTERMJ likes this.
rockflyertalk is offline  
Old Mar 5, 2021, 11:56 am
  #47  
 
Join Date: May 2019
Posts: 71
Have changed my password, but can’t get into account now. So seems to be wider issue. Good job it’s not a Friday evening at JFK like back in the day...
Young82 is offline  
Old Mar 5, 2021, 11:57 am
  #48  
 
Join Date: Oct 2019
Location: clue is in the nym
Programs: BA Gold, TP Gold, VS Gold, Hilton Diamond, IHG Diamond, Hyatt Globalist, Marriott Platinum
Posts: 833
Originally Posted by Nephoi
wonderful...

"We will not contact you by phone and ask for your password - please do not reveal your password to anyone claiming to be from British Airways. If you need to contact us, you can do so via our contact centres."

i got a text with the verification. thats a contact by phone.

You got a text. Nobody asked you for your password. What's the problem?
scoonee and flatlander like this.
southlondonphil is offline  
Old Mar 5, 2021, 12:15 pm
  #49  
 
Join Date: Oct 2012
Location: Helvetia
Programs: AS; BA Silver; UA; HH Gold; Sprüngli Connaisseur
Posts: 2,912
I'm kind of surprised that SITA would have any actual data as they were primarily a private networking company, at least back in the days when I had anything to do with them. Which was basically setting up RIP to send data over SITA to Lockheed-Martin instead of over the public internet. Then again, that was about 20 or so years ago so things have probably changed.

But, as I like to say, if you're any good in IT, you're not going to stay in aviation.
greg5 is offline  
Old Mar 5, 2021, 12:17 pm
  #50  
Moderator, Emirates
 
Join Date: Oct 2012
Location: Where My Heart Is
Programs: BAEC Silver, FB Platinum, KQ Asante Gold, Shebamiles Blue, Emirates Blue
Posts: 3,386
Able to change password and sign in now.
Saltire74 is offline  
Old Mar 5, 2021, 12:21 pm
  #51  
 
Join Date: Apr 2006
Location: MAN
Programs: F
Posts: 2,898
Used the forgot my password link, set a new password using my membership number which is what I always use, but could not log in with the new password. I tried switching to my email address but that did not work either with the new password. Finally I guessed at a username without an "@" (although I do not recall setting one) and that let me through to the send SMS and pick yet another password page. I could now login using the guessed-at username and the second new password.

So .. I went to my account details where I see that "username" is UNSET and my email address is meant to be my username. I have changed this to specifically be the guessed-at username and now it both shows it in my account details and I can continue to login.

Holy c**p.
redshift27 is offline  
Old Mar 5, 2021, 12:21 pm
  #52  
 
Join Date: Nov 2016
Location: Sussex
Programs: BA; IHG; LHW; Hilton
Posts: 788
Used email

Originally Posted by rockflyertalk
Good plan. I would urge anyone reading this to give them time to fix whatever is broken. Just note whatever is held in your account as a just in case. But I’m sure it will be fixed if they’ve triggered that email.
having gone to the trouble of changing my password, twice, I also then found it did not recognise my membership number. However – I did work when I used my BA email address instead along with the new, new – that second new – password 🙈🙉
SxMan is online now  
Old Mar 5, 2021, 12:23 pm
  #53  
 
Join Date: Oct 2019
Location: clue is in the nym
Programs: BA Gold, TP Gold, VS Gold, Hilton Diamond, IHG Diamond, Hyatt Globalist, Marriott Platinum
Posts: 833
Originally Posted by greg5
I'm kind of surprised that SITA would have any actual data as they were primarily a private networking company, at least back in the days when I had anything to do with them. Which was basically setting up RIP to send data over SITA to Lockheed-Martin instead of over the public internet. Then again, that was about 20 or so years ago so things have probably changed.

But, as I like to say, if you're any good in IT, you're not going to stay in aviation.
They market a Passenger Management System called Horizon which appears to be the software that was compromised.
greg5 likes this.
southlondonphil is offline  
Old Mar 5, 2021, 12:26 pm
  #54  
 
Join Date: May 2009
Location: London
Programs: BAEC
Posts: 2,741
I’m as infuriated as everyone else. If the company didn’t have my password, why is BA making me change it ? This makes no sense whatsoever. Total and unnecessary hassle alround...
skippythelizard likes this.
bafan is offline  
Old Mar 5, 2021, 12:29 pm
  #55  
 
Join Date: Apr 2012
Location: LCY is always preferred
Programs: BAEC Gold, IHG Silver, HHonors Gold
Posts: 1,026
Using the email address worked for me. I managed to complete the new password and then changed the ID from my BAEC number to my email and I'm in fine. Glad actually, as I'm just about to book my first flight in ages (for 2022!!!)
SpurMan is offline  
Old Mar 5, 2021, 12:32 pm
  #56  
 
Join Date: Oct 2019
Location: clue is in the nym
Programs: BA Gold, TP Gold, VS Gold, Hilton Diamond, IHG Diamond, Hyatt Globalist, Marriott Platinum
Posts: 833
Originally Posted by Fontana
There's no point in trying to change your password, BA have most likely locked everyones out and will probably do a slow slow approach, especially after what happened the last time. They won't be taking any risks. BA will be swamped with many callers now, better to leave it for few days. Unlikely, anyone will get into your account as its locked out.
It may seem like a sledgehammer measure to block everybody's accounts because a 3rd party provider with no direct connection to BA's systems has suffered a breach, but remember that BA is coming off a massive fine for inadequate security measures resulting in a huge breach of their own, so one can certainly understand them erring on the side of caution / overreacting (choose your preference) to this incident
southlondonphil is offline  
Old Mar 5, 2021, 12:35 pm
  #57  
 
Join Date: Nov 2006
Programs: Seniors Bus Pass
Posts: 5,530
Originally Posted by bafan
I’m as infuriated as everyone else. If the company didn’t have my password, why is BA making me change it ? This makes no sense whatsoever. Total and unnecessary hassle alround...
That is probably because their experience is that many people use the same password on multiple sites. As is is linked to an email address, when one site is hacked and their emails are taken then the hackers will just try the other carriers and get in on plenty of the muppets accounts.

As a data reference point I got an email from Aegean before I saw the BA one informing me about the hacked Star Alliance issue:
Dear Miles+Bonus member,

AEGEAN was notified by SITA (Société Internationale de Télécommunications Aéronautiques), a third party system provider of another Star Alliance airline, that it had experienced a cyber security incident involving certain passenger data that was stored in its passenger service system which is used to support airline operations.

In particular, the passenger data impacted by this incident was the name, membership number and tier status of Frequent Flyer Program members. These are the data made available by AEGEAN to Star Alliance and through SITA to other Star Alliance airlines, to allow Frequent Flyer status recognition around the world.

The incident did not affect members’ password or any other sensitive personal information (email, reservations, ID card or payment card information) which were not available in this database as they are not shared by AEGEAN or the other Star Alliance member airlines.

There is no evidence that your account data in AEGEAN Miles+Bonus program have been compromised or misused and no action is required on your side. The incident did not affect AEGEAN own systems in any way.

By this proactive communication, we intend to make you aware of the above and we kindly ask you to address or report at [email protected] any relevant query or issue.

Best Regards,

Miles+Bonus
antichef is online now  
Old Mar 5, 2021, 12:37 pm
  #58  
 
Join Date: Mar 2021
Programs: BA Executive
Posts: 1
No it doesn't always work. Tried the password forget and it won't accept any information from me. Put my email address in and it says another member already has that address! Any suggestions?
TPenny is offline  
Old Mar 5, 2021, 12:46 pm
  #59  
 
Join Date: Jun 2012
Programs: IHG Spire Ambassador, Club Carlson Gold, HHonors Gold, Best Western Diamond Select, BA Blue
Posts: 1,335
Managed to change my password for ba.com using the 'Forgot details' option. Now I can't log in at all. Doesn't recognise my email address or membership number at all now. How difficult can this be?
rumbataz is offline  
Old Mar 5, 2021, 12:50 pm
  #60  
 
Join Date: Jun 2012
Programs: IHG Spire Ambassador, Club Carlson Gold, HHonors Gold, Best Western Diamond Select, BA Blue
Posts: 1,335
Something I noticed in the email from BA about this data breach and resetting of passwords:

Please log into your account and reset your password
Please create a new password that you have not used elsewhere
Once your password has been reset and you have completed a verification step, you will be able to regain full access to your account
What is this verification step?
rumbataz is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.