Cathay Pacific flags data breach affecting 9.4M passengers
reuters.com
reuters.com
I wonder how many companies who have 'leaked' data recently are doing these things. Granted, it will never catch all bugs, but avoiding these things is negligence, which should be punishable.
Criminalization is wrong, though. Put the company to death, that's enough. Even the high penalties of GDPR already cause changes of management behavior (at least where I work).
We go to great extent to not have any kind of Personally Identifiable Information, because the liability is way too big.
It really sucks when a client accidentally send us a list of their customers email and we have to clean up everybody's inbox.
I do not want any of your data, above that which I must hold for the service to be useful. It’s just a liability.
See also: Marco Arment, maker of the Overcast podcast player, pushing people to take their accounts anonymous [0]. It’s just good business sense at this point.
I also plan on having zero trackers. I’ll just get over the fact that I’ll have no visibility of users on my site other than what I can glean from public forums or, you know, actual paid sign-ups. It’s all too fraught with leak risk and I can’t be bothered.
If the one billion odd people affected by major data breaches since 2005¹ all experienced some significant difficulty as a result, we could probably expect a louder outcry and subsequent changes in behaviour by those we entrust(?) our personal identifying information to.
I've been online since well before 2005, and the worst I've experience is one debit card being cancelled due to a failed fraudulent transaction attempt ~10 years ago, and ~2 months ago a successful fraudulent transaction of AU$13.36 which I noticed immediately (thanks mobile banking app notifications), which resulted in the me calling and cancelling the card and the charge being reversed.
Of course, we're all paying more in fees due to insurance against such events, but that appears to be an inconvenience that most people simply don't rate.
From: Whoops we gave a loan to a stranger because they tricked us!
To: You owe us money because someone stole the core of yourself, from yourself, without you noticing
The police get to move a whole load of theft out of their crime statistics as it modernizes, and the banks get to avoid lots of ‘red tape’ and can decide how nice they want to be to each victim (or rather, how profitable being nice is).
929 million users / customers affected by major data breaches since 2005.
There's probably at least some / a whole lot of overlap in some, but still...
Thusly, it'd be unusual if any particular individual hasn't had at least some of their identity go astray.
That being said, Cathay Pacific has been really going downhill these past couple of years. Not surprised that their IT side of things are effected as well.
Then again...someone complacent enough to get that far behind in infrastructure probably doesn't have any chance of that being thought of/appoved.
I see you've worked in the enterprise? :-)
Another reason is that nobody knows how it really works. The people who knew have long retired. The fear is updating it will likely introduce subtly new behavior and new bugs that everyone is scared of touching it.
On that note; any recommendations for Aussie banks that have a secure and modern interface?
I love that they're relatively modern for Australian standards (fast payments, no fees ever, basically) so i'd love to endorse them, but i, too, am on the lookout for a replacement bank that has e.g. MFA with TOTP or a physical challenge-response box like my otherwise overpriced ABN bank account gave me back in 2002, in the Netherlands...
So i, too, am all ears for recommendations.
EDIT: and once you're in internet banking, you can willy nilly transfer cash out if you either use a "saved address" (someone you've paid before) or you'd need to hijack my mobile number. But $deity knows that's easy - just claim you own a number and get it ported over to a new service no-questions-asked. Facepalm, really.
Lots of their app functionality is now handled through AWS from what i've heard.
Make the fine directly proportional to: number of people affected * bits of leaked data for each user.
>860,000 passport numbers, about 245,000 Hong Kong identity card numbers, 403 expired credit card numbers and 27 credit card numbers with no card verification value (CVV) were accessed in the breach.
Those numbers don't seem to add up to anything close to 9.4 million. Feel like I'm missing something.
It doesn't make a lot of sense however I parse it, but that's the only thing that makes the numbers work.
It is unclear from any reporting as to how this technically happened, which is a shame but hopefully that will be made public in the coming days. Some other outlets[0] have an interesting statement:
> The breach also included details about where each passenger had traveled and any comments made by customer service representatives. The amount of data accessed varied among passengers.*
Based on those details, and the mention of 'no passwords were compromised', chances are this breach has come from an internal helpdesk type system, or possibly CRM. If however the statement around the passwords changes, that opens up a few other possibilities.
What this doesn't sound like, are the attacks we saw on British Airways[1] and Ticketmaster[2], where javascript was injected into the payment pages to vacuum up payment details from customers.
The statement around "The company has no evidence that any personal information has been misused" is always an interesting one, and is one of the many reasons I created my startup Breach Insider[3], so that data breaches like this could be detected much sooner (not 7 months later, as we have seen here), with minimal false positive alerts, and definitive evidence if any data has been misused. By using real email addresses that are unique to each company/business, you can be sure to find out if that data ever leaks & is abused for things like spam or phishing.
[0] https://www.theverge.com/2018/10/24/18019958/cathay-pacific-...
[1] https://www.britishairways.com/en-gb/information/incident/da...
[2] https://www.riskiq.com/blog/labs/magecart-ticketmaster-breac...
PCCW the main local telco uses Hong Kong ID numbers as passwords by default, or at least they used to do so. This means that this database contains usernames and passwords in cleartext for a significant number of users who have never changed their accounts.
Well that's good! My precious password that can be easily changed wasn't leaked!
> Cathay in a statement said accessed data includes names of passengers, their nationalities, dates of birth, telephone numbers, email and physical addresses, passport numbers, identity card numbers and historical travel information.
oh...
So getting someone's name and personal information (that yes, can also be used for identity theft) is not as bad as now having a list of names and passwords to try to use on bank websites, for example.
So my passport number leaking is personally much worse for me than if my password leaked (which I'm very careful to protect).
I suspect you might find that a different passport with a different number, expiry date, or even nationality but the same name and date of birth would work equally well.
Nope. All of the information must match, and they even (excruciatingly) compare the signature in my passport to the one they have on file. At another bank where I used only my HKID to open the account, I'm not permitted to use my passport.
Which means you need to have a photo of any signature you register with a bank there or later on forms you sign will be rejected.
The questions are easily bruteforced through so I'd say it's a real issue. I'm deeply concerned by that leak because of that.
And I find it more concerning than BA leaking my financial details without my passport number (which also recently happened and led me to cancel one of my credit card)
To expand on the identity theft part, all the leaked info are enough to open an online low tier bank account (one might need to forge random images to prove identify and residency, but that’s super basic photoshopping, as it only needs to be scan quality). In particular the passport informations makes it a ton easier.
From there we move from simple identity theft, to possessing a bank account under the name of the victim, which opens the door to so many money schemes (no service will double check when asked to change bank info to another account with the same owner)