Delta: Data of ‘several hundred thousand’ customers exposed
seattletimes.com
seattletimes.com
It's not used “like a PIN” as a second factor with the physical card as the first factor, it is used to make online and certain other uses of a card equivalent to card-present transactions with no substantive second factor.
Disgusting, how was this buried for 6 months?
> The Atlanta-based airline said that it wasn’t sure whether customers’ information was actually compromised by malware that it believes was in software used by (24)7.ai, which provided the airline with online chat services for customers, for about two weeks.
Your website, your liability. This is Delta's fault. By letting third-party Javascript execute on your webpage, that's basically a remote code execution right there. That's like giving an outside company root on your database, or domain controller. Maybe this will serve as a wake-up call for web devs, instead of piling more and more terrible JS onto a page.