Data belonging to customers of numerous airlines from around the world has been compromised, following a hack that occurred on SITA servers . SITA is a multinational IT company that provides IT and telecommunications services to the aviation industry. The company provides its services to approximately 400 members and 2,800 customers worldwide. It is worth noting that around the world, almost every passenger flight relies on SITA technology

A few days ago, the company announced that it had suffered a “highly sophisticated security incident” in which hackers gained access to data stored on SITA Passenger Service System (PSS) servers. The total number of customers affected by the breach remains unknown.
SITA PSS operates systems for airlines. After confirming the severity of the security incident on 24 February 2021, SITA took immediate action by contacting affected customers as well as organisations using its technology.

The company states in its related notification the following: “SITA acted quickly and began implementing targeted mitigation measures. The issue remains under ongoing investigation by SITA’s security incident response team with the support of leading external cybersecurity.”
According to Security Affairs, the cyberattack affects several airlines, including Singapore Airlines, Lufthansa, Malaysia Airlines, Cathay Pacific, SAS-Scandinavian Airlines, Finland's Finnair, Jeju Air, and Air New Zealand.

Specifically, Singapore Airlines disclosed the security breach last week, while confirming that approximately 580,000 members of its frequent flyer program, KrisFlyer, have been affected.
In addition, the airline contacted its customers and informed them that it does not use the SITA PSS, but at least one of the 26 Star Alliance uses the PSS system and SITA has access to some frequent flyer program data from all Star Alliance airlines.

As reported by BleepingComputer, Star Alliance received a notification from SITA regarding the PSS breach on February 27. Star Alliance said it was informed that not all of its member airlines were affected, but did not rule out the possibility.
According to the affected airlines, hackers gained access to some customer data, such as name and membership number. There is currently no evidence to suggest that sensitive or financial data was compromised.
