A hackathon held in 2017 resulted in a Flight Center data breach when the passport and credit card numbers for 6,918 customers were accidentally exposed in a dataset used by the competition participants.

As announced by the Australian Information and Privacy Commissioner Angelene Falk, Flight Center breached Australian privacy principles by using data for purposes other than the reason it was originally collected.
When the breach was first reported there weren't many details.
It has now been revealed that Flight Center leaked the data during a three-day “design jam” in March 2017 “to create technology solutions for travel agents to better support customers during the sales process.”
It was the first time Flight Center had organized such an event, and participants were not required to sign a non-disclosure agreement to take part.
A total of 16 teams participated in the hackathon-style event and were given access to a dataset from 2015 to 2016.
Falk said Flight Center reviewed “a top sample of 1000 rows for each data file in the dataset, to ensure that the data did not contain any personal information.”
However, on the last day of the “design jam,” a participant spotted credit card information in an “unstructured free text field in the data” and notified the company.
After further examination, Flight Center said the field "incorrectly included details of 4011 credit cards and 5092 passport numbers for 6918 people."
“In addition, 475 usernames and passwords and 757 strings containing customers’ dates of birth were exposed,” the Commissioner wrote.

According to the information, approximately 6918 people were affected in total by the incident, while there were 1012 customers for whom Flight Center did not have sufficient contact information and was thus unable to notify them.
The remaining affected customers were notified on July 7, 2017.
Flight Center said there was no evidence the data was misused .It confirmed with all participants in the “design jam” that the data was “destroyed.”
The company said it scanned its IT systems after the incident “to identify and remove any other instances of incorrect storage of credit card or passport details” and has been performing weekly scans since then.
It also improved its “systems and software to ensure that credit card information and passport information cannot be stored in free-text data fields.” A third-party intelligence specialist was hired to monitor social media and the dark webto see if leaked data about its customers was published, and it updated its privacy and data management policies.
Commissioner Falk said Flight Center does not have to compensate victims of the breach, although it had already paid $68,500 in passport replacement costs, as well as an undisclosed amount for credit monitoring services for those affected. The company also will not face any further repercussions, with the Commissioner saying it had provided honest answers throughout the investigations and was no longer holding “design jam” events.
