21 September 2022

American Airlines had waited two months to disclose a data breach


American Airlines had waited two months to disclose a data breach

American Airlines, a major US-based airline, has disclosed a data breach where an unauthorized party gained access to employee accounts via a phishing campaign.

In a notification letter sent to impacted individuals the company said that the breach was discovered in July 2022, and may have affected customer and employees’ personal information, such as name, date of birth, mailing address, phone number, email address, driver’s license number, passport number, and/or certain medical information.

“Upon discovery of the incident, we secured the applicable email accounts and engaged a third party cybersecurity forensic firm to conduct a forensic investigation to determine the nature and the scope of the incident. Our investigation determined that certain personal information was in the email accounts. We conducted a full eDiscovery exercise and determined some of your personal information may have been contained in the accessed email accounts,” the notice reads.

There is no evidence that exposed personal information was misused, the company said.

Recently, the ride-hailing company Uber Technologies and video game publisher Rockstar Games also disclosed similar breaches.

Back to the list

Latest Posts

Cyber Security week in review: December 2, 2022

Cyber Security week in review: December 2, 2022

The world in brief: Samsung, LG, Mediatek certificates used to sign Android malware, researchers detail new exploit framework, and more.
2 December 2022
Security researchers unintentionally crash KmsdBot botnet

Security researchers unintentionally crash KmsdBot botnet

The malware lacked an error-checking mechanism, which allowed the researchers to deactivate it.
1 December 2022
New Heliconia framework exploits n-day flaws in Chrome, Firefox and Microsoft Defender

New Heliconia framework exploits n-day flaws in Chrome, Firefox and Microsoft Defender

The researchers have linked the framework to a Spain-based software company.
1 December 2022