
One of India 's largest airlines has suffered a security breach that exposed the data of 1.2 million passengers, including flight information. According to TechCrunch , a security researcher used brute-force to gain access to SpiceJet's systems, and said that cracking the security code was not particularly difficult.
The passenger information was found in an unencrypted database on one of SpiceJet's systems. The researcherthe database included information such as the passenger's name, phone number, date of birth and email address.
The database also included the price of the passengers' tickets and their flight numbers. This information was highly confidential, as the names of the passengers included some government officials.
The researcher tried to alert SpiceJet about the database, but was unable to get in touch with them. He then alerted CERT-In, a government agency that manages India 's cybersecurity . The agency acknowledged the security issue and informed SpiceJet about it. So far, the airline has taken the necessary steps to avoid a chaotic situation in terms of data leakage.
What did SpiceJet respond to?
A SpiceJet spokesperson said the airline is committed to the security of any data related to its passengers and that the company's systems are now up to date and protected.
SpiceJet has about 13% of the market in India. India is the fastest growing aviation market in the world, with about 12 million people in the country traveling by air every month and the number is growing rapidly. SpiceJet has about 600 active aircraft, including international flights to Dubai and Hong Kong.
