International airline Cathay Pacific has been fined £500,000for failing to effectively protect the personal data of customers .
The Information Commissioner's Office (ICO) said that between October 2014 and May 2018, systems Cathay Pacific's security. This resulted in the exposure of customers' personal data. Of this data, 111,578 belonged to UK citizens and around 9.4 million to people around the world.
Due to inadequate security, hackers were able to gain access to Cathay Pacific's systems and steal customers' personal information. The compromised data includes: names, passport and ID details, dates of birth, postal and email addresses, phone numbers and travel information.
An investigation by the data found that there were many errors in the way the airline handled cybersecurity. These errors led to the data breach, which was discovered four years later (October 2014 – May 2018).
What were these security mistakes?
The commissioner said Cathay Pacific's backups were not password-protected or encrypted. In addition, the operating system and servers were not up-to-date despite a known vulnerability, and there was insufficient virus protection.
The company was also accused of lacking a software-patching management strategy and allowing users to remotely access systems without multi-factor authentication.
Cathay Pacific noticed suspicious activity in March 2018, about four years after the initial breach, when hackers had already gained access to customer data and had attempted to penetrate other areas.
After that, the airline hired a security company to investigate the case and reported the incident to the information protection commissioner
"People expect that the personal information they provide to a company will remain secure and protected from any fraud. That simply did not happen here," said Steve Eckersley from the Information Protection Office.
This breach was concerning as it related to a particularly large number of security deficiencies in Cathay Pacific's systems.
As a result, Cathay Pacific was fined £500,000, the maximum amount given under the Data Protection Act 1998.
"The company would again like to express its regret and apologize for this incident," Cathay Pacific said.
"Significant sums have been spent on infrastructure and safetyover the past three years, and investment in these areas will continue," the airline added.
The Cathay Pacific data breach was discovered before the GDPR (in May 2018). If the discovery had been made later, the fine would have been higher.

