Airlines (SAS) has issued a statement informing travelers that a recent long-term outage of its website and mobile app was due to a cyberattack, which also led to data customer. The attack took place on February 14.

During the cyberattack , a disruption in the airline's online system made passenger data visible to other passengers. Customers reported logging into the SAS app and accessing other accounts. The information included contact details, upcoming and past flights, and the last four digits of their credit card numbers.
“Last night SAS, along with many other companies, was subjected to a cyberattack that resulted in the disabling of our website and app for a few hours. In addition, some data became visible to other passengers who were active during the ongoing attack,” SAS said in statement .
See also: Citrix patches vulnerabilities in Workspace, Virtual Apps and Desktops
Scandinavian Airlines, which operates 131 aircraft and flies to 168 destinations, said the chances of the leaked data being misused or abused were minimal, as the financial information leaked was not extensive and difficult to use. It also assured passengers that no passport information was exposed.
However, the exposed data (full names and contact details) could be used by malicious actors and scammers to carry out highly targeted phishing.
Scandinavian Airlines stressed that it is cooperating with the Civil Aviation Agency (CAA) and the police regarding this specific cyberattack and data leak.

“We are closely monitoring the situation and continue to work to analyze and assess the attack and its consequences, as well as to take preventive measures“.
A data breach, such as the one that affected Scandinavian Airlines customers, can cause serious damage to a company’s reputation and financial health. Unfortunately, data breaches are becoming increasingly common, and it’s important for every business to have a plan in place in case an attack.
See also: Hyundai and Kia release patch for dangerous security flaw
'Anonymous Sudan' claimed responsibility
According to TheRecord, “Anonymous Sudan,” a hacktivist group, claimed responsibility for the attack on SAS and published a related announcement via their Telegram.
The group said it attacked the SAS because of an incident that took place in front of the Turkish embassy in Stockholm, Sweden, on January 21, 2023. A far-right nationalist group burned a copy of the Holy Quran in protest of Turkey's objections to Sweden's accession to NATO.
Muslims around the world, including Sudanese citizens, have strongly criticized this act. As a result, Scandinavian Airlines – Sweden’s (and Norway-Denmark’s) leading airline – became a target for hacktivists who wanted to show their disapproval.
See also: NPM: 'Supposed' speed tester packages installed crypto miners!
"We will continue the attacks in a large and violent manner if an official apology is not issued by the Swedish government regarding the burning of the Quran," the organization said.
This week, SVT, Sweden's main public television station, was also attacked, resulting in its temporary shutdown .
Source: www.bleepingcomputer.com
