HomeSecurityAmerican Airlines learned how it was breached

American Airlines learned how it was breached

American Airlines says its Cyber ​​Security Response Team discovered a newly disclosed data breach from the targets of a phishing campaign that used an employee's compromised Microsoft 365 account.

American Airlines learned how it was breached

As the airline said in filings with the New Hampshire Attorney General's Office, after receiving these phishing reports, American's CIRT discovered unauthorized activity in the company's Microsoft 365 environment.

The investigation also revealed that the attacker had access to multiple employee accounts (also compromised through phishing attacks) and used them to send more phishing emails to targets that the company has not yet disclosed.

See also: Multi-million dollar credit card fraud operation uncovered

The company added that the team members' accounts also provided access to employee files stored on the cloud-based Sharepoint service.

“Through its investigation, American was able to determine that the unauthorized agent used an IMAP protocol to access the mailboxes. The use of this protocol may have allowed the unauthorized agent to synchronize the contents of the mailboxes with another device,” a legal notice describing the security incident states.

“American Airlines has no reason to believe that the purpose of the access was to synchronize the contents of the mailboxes. Based on the facts, it appears that the unauthorized agent was using the IMAP protocol as a means of accessing the mailboxes and sending phishing messages.”.

While the airline believes the risk to affected individuals is remote, it notified affected individuals of the data breach on September 16.

As the company revealed in the notification letters, the personal information exposed in the attack may have included employee and customer names, dates of birth, mailing addresses, phone numbers, email addresses, driver's license numbers, passport numbers , or certain medical information.

See also: Ukraine dismantles group that stole 30 million accounts and sold them on the dark web

American Airlines

Data breach affects more than 1,700 customers and employees

When asked for more details about this incident, American Airlines' Director of Corporate Communications, Andrea Koos, declined to share the exact number of people affected by this data breach, saying it was a "very small number.".

However, as the company later revealed in a filing with the Maine Attorney General's Office, the data breach affected 1,708 American Airlines customers and team members.

The company says it will offer those affected two years of free membership to Experian's IdentityWorks with identity restoration services and up to $1 million in identity theft to help detect and resolve identity theft.

"While we have no evidence that your personal information has been compromised, we recommend that you sign up for Experian credit monitoring," American Airlines added.

“In addition, you should remain vigilant, including by regularly checking account .”

See also: Sophos Firewall: Critical vulnerability exploited by hackers

The airline was hit by another data breach in March 2021 when global aviation information technology giant SITA said hackers breached its servers and gained access to the Passenger Service System (PSS) used by many airlines worldwide, including American Airlines.

American Airlines is the world's largest airline by fleet size. It has more than 120,000 employees and operates nearly 6,700 flights daily to approximately 350 destinations in more than 50 countries.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS