FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Cathay Pacific | Cathay (https://www.flyertalk.com/forum/cathay-pacific-cathay-487/)
-   -   9.4 million passengers’ data stolen from CX (https://www.flyertalk.com/forum/cathay-pacific-cathay/1937167-9-4-million-passengers-data-stolen-cx.html)

Dave510 Oct 24, 2018 8:51 pm

I don't think Cathay's IT heads deserve all the blame. Most corporations think of IT as an expense that should be minimized, and Cathay has already been cutting costs across the board, heavily. There's not much IT can do if they're extremely understaffed and under budget. The fact that IT continues to be lacklustre despite personnel change seem to suggest the issue is more than just incompetence on the part of the IT department leadership.

kaka Oct 24, 2018 9:22 pm


Originally Posted by SuloL (Post 30352974)
This is a really worrying trend, and 7 months for notification is totally unacceptable. Perhaps a lot of people affected were EU citizens and EU could slap CX with a good fine? :p

Now I'm thinking if my situation is related, where AM has done a grande f**k-up recently.

Called in the other day to book awards, agent started verification. When asked about passport issuing country (been asked and have answered this many times before) she told me my answer was wrong! She claimed that my passport nationality should be HK. Never even had a HK passport! And the last time I booked awards (1month back) my answer to the issuing country (the real one) was good to go. Wondering what the hell is going on with their customer data mgmt...

yes
any bno holders (or expired once as long as you did not renounce it) can do this on top of the normal suspects of eu28 passport holders

peasant Oct 24, 2018 9:28 pm

If you look at the org chart, there is no CIO/ Director IT anymore. The IT general managers report direct to CCO (Chief Commercial Officer) Who is also in charge of sales/ marketing/ cargo/ customer experience...

Nicc HK Oct 24, 2018 9:56 pm

Bl**dy CX
 
Now I am seriously annoyed, just recieved this from CX

Dear Mr Nicc
We are contacting you to make you aware of a data security event that involves some of your personal data. We are very sorry for any concern that this event may cause you, and this notice will provide you with information about what happened and how we can assist you.

What happened?

As part of our ongoing IT security processes, we discovered unauthorised access to some of our passenger data.

We initially discovered suspicious activity on our network in March this year. Upon discovery, we took immediate action to contain the event, to commence a thorough investigation with the assistance of a leading cybersecurity firm, and to further strengthen our IT security measures. Unauthorised access to certain personal data was confirmed in early May. Since that time, analysis of the data has continued in order to identify affected individuals and to determine whether the data at issue could be reconstructed.

We have no evidence that any personal data has been misused. We recommend that you follow the steps outlined in this notice to help protect yourself against potential risks.
What information was involved?

The following types of personal data about you were accessed:
  • HKID Number
  • Name
  • Nationality
  • Title
  • Travel Document Number
Your travel or loyalty profile was not accessed in full, and your password was not compromised.
What are we doing to help?

You can find more information at our dedicated website, infosecurity.cathaypacific.com.

Where available in your country, we are offering ID monitoring services to affected passengers. This will be provided by Experian, a global data and information service provider. This service (IdentityWorks Global Internet Surveillance) monitors if your personal data may be available on public websites, chat rooms, blogs, and non-public places on the internet where data can be compromised such as dark web sites.

This is an optional service, and how much information to include in the identity monitoring is completely at your discretion.

The information you provide to Experian will only be used by Experian for the sole purposes of identity monitoring. It will not be published to any other entity.

Please visit the following website: http://www.globalidworks.com/identity1 and click the Get Started button to activate this 12 month complimentary service. You can then enter your personalized activation code: SCREW CX to start your IdentityWorks Global Internet Surveillance.

We have notified, or are notifying, the relevant authorities and the Hong Kong Police.

What should I do?

Although no-one’s travel or loyalty profile was accessed in full and no passwords were compromised, as best practice, we recommend that you consider:
  • changing your passwords regularly;
  • checking for any suspicious activity; and
  • being vigilant against phishing or other attempted scams.

To date, there is no evidence of misuse. However, it is possible that the personal data could be misused for unauthorised purposes such as fraud or identity theft.

As mentioned above and where available in your country, we are offering ID monitoring services to affected passengers. Please visit the following website : http://www.globalidworks.com/identity1 and click the Get Started button to activate this 12 month complimentary service using your personalized activation code above.


For more information

If you have any further questions about the event, you can contact us by:
  • visiting our dedicated website at infosecurity.cathaypacific.com;
  • call our dedicated call centre (toll free numbers available at infosecurity.cathaypacific.com); or
  • emailing us at [email protected].
We want to reassure you that there is no impact on flight safety as the IT systems affected are totally separate from our flight operations systems, and that we continue to take measures to enhance our IT security. Your safety and security remains our top priority.


Yours sincerely,

Rupert Hogg
Chief Executive Officer
Cathay Pacific Airways Limited

For your information:

Asia Miles is owned by, and provided to members by Cathay Pacific Airways Limited, and is managed and operated by Asia Miles Limited, a wholly owned subsidiary of Cathay Pacific Airways Limited, as an agent of Cathay Pacific Airways Limited.

Hong Kong Dragon Airlines Limited is a wholly owned subsidiary of Cathay Pacific Airways Limited and Cathay Pacific Airways Limited manages and provides IT support services to Hong Kong Dragon Airlines Limited.

The ID Monitoring Services are available in Australia, Brazil, Canada, France, Germany, Hong Kong, India, Ireland, Italy, Mexico, Netherlands, New Zealand, Norway, Poland, Singapore, United Kingdom and United States.

FlyPointyEnd Oct 24, 2018 10:30 pm

Looks like a lot of DMs are affected....I guess we get priority also when our data get stolen

frankyguy Oct 24, 2018 10:43 pm

I think that's it for CX for me. 14 years as a DM and the airline is not even a shadow of its former self. I can put up with the declining soft and hard DM benefits, the bad food and bad wine but will not tolerate what appears to be such a blase attitude to the breach of personal data security. Seven months? Bye CX.

FlyPointyEnd Oct 24, 2018 11:30 pm


Originally Posted by Nicc HK (Post 30353151)
The ID Monitoring Services are available in Australia, Brazil, Canada, France, Germany, Hong Kong, India, Ireland, Italy, Mexico, Netherlands, New Zealand, Norway, Poland, Singapore, United Kingdom and United States.

so what happens if the ID Monitoring Services is not available?

Nicc HK Oct 24, 2018 11:37 pm

What gets me is that these arses knew for months and said nothing. That means through their incompetence/negligence we have all been put at unknowing and unnecessary risk. CX should have advised affected people as soon as they knew.

I am going to discuss this with lawyers.

FlyPointyEnd Oct 24, 2018 11:53 pm


Originally Posted by Nicc HK (Post 30353339)
What gets me is that these arses knew for months and said nothing. That means through their incompetence/negligence we have all been put at unknowing and unnecessary risk. CX should have advised affected people as soon as they knew.

I am going to discuss this with lawyers.

Class action?

fast03 Oct 24, 2018 11:53 pm

Got the same email as Nicc.

I’m quite angry with the 7 months notice to the public to be honest.

If there was a breach to my very personal data that I have entrusted a company to, I would expect to be notified after a considerate time when due dilligince and verification of breach has been completed. Im sure there are GDPR consequences cause of this.

7 months after the fact is a blatant attempt to hide it under the rug and the justification for the delay is to “avoid causing unnecessary panic among customers” is simply BS.

Over the past year(s) I’m really finding it hard to see if the airline has actually done any good for its customers or has actually kept us a priority for management decisions.

FlyPointyEnd Oct 24, 2018 11:54 pm


Originally Posted by fast03 (Post 30353378)
Got the same email as Nicc.

I’m quite angry with the 7 months notice to the public to be honest.

If there was a breach to my very personal data that I have entrusted a company to, I would expect to be notified after a considerate time when due dilligince and verification of breach has been completed. Im sure there are GDPR consequences cause of this.

7 months after the fact is a blatant attempt to hide it under the rug and the justification for the delay is to “avoid causing unnecessary panic among customers” is simply BS.

Over the past year(s) I’m really finding it hard to see if the airline has actually done any good for its customers or has actually kept us a priority for management decisions.

I agree, they did admit that they confirmed it in May, it still took them 5 months to disclose the matter.

kaka Oct 25, 2018 12:12 am


Originally Posted by FlyPointyEnd (Post 30353381)
I agree, they did admit that they confirmed it in May, it still took them 5 months to disclose the matter.

spoke w some tech ppl and lawyer people.

if you read between the lines, they did not say they were hacked (read BA on 7sept). and that they had “too many” IT contractors.

seems like they got some dodgy contractors.

and if you look at the scope of what info was leaked, pax info (we as ffp are worried) and past travel records. not so much of cc info (so they may not be after the money)...

plunet Oct 25, 2018 12:22 am


Originally Posted by cathaychap (Post 30352747)
I believe what Cathay is saying is that nobody has had their full profile taken. It's more bits of data taken. Like a few numbers of a passport and half an email address. At any rate, visit infosecurity.cathaypacific.com if concerned. The good thing is that CX, unlike BA, has a coordinated response to the threat. I had to cancel two credit cards with the BA thing.

I really have to disagree. BA at least notified the affected customers promptly and although the news of the loss was unpalatable they managed to pull off the notification quickly, how some of the card issuers have responded to the breach has been haphazard but that is not BAs direct fault.

Cathay have been sitting on this for 7 months and have been irresponsible in their inaction and for EU citizens would have automatically been guilty of an unnecessary delay if the breach had happened since GDPR had been inacted.

blum81 Oct 25, 2018 12:25 am


Originally Posted by plunet (Post 30353447)
I really have to disagree. BA at least notified the affected customers promptly and although the news of the loss was unpalatable they managed to pull off the notification quickly, how some of the card issuers have responded to the breach has been haphazard but that is not BAs direct fault.

Cathay have been sitting on this for 7 months and have been irresponsible in their inaction and for EU citizens would have automatically been guilty of an unnecessary delay if the breach had happened since GDPR had been inacted.


Agree. a lot can happen in 7 months. Customers could have taken their own precautions to protect themselves such as canceling credit cards, replacing passports, or even doing their own credit and ID checks.

sxc Oct 25, 2018 12:36 am

No wonder the lounges are so crowded, with all this data for identity theft :D


All times are GMT -6. The time now is 1:34 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.