Japan Airlines (JAL)'s network was attacked by hackers who managed to steal personal data from between 110,000 and 750,000 customers.
Last week, JAL system administrators discovered a breach in servers used to store and manage personal customer data, including names and addresses of customers enrolled in its frequent flyer program, which offers discounts and gifts to frequent flyers.
The stolen information was sent to a server in China
According to the “Japan Times”, an investigation found that 23 computers were infected with malware.
These computers were sending data to a server located in Hong Kong. However, this does not mean that the perpetrators are Chinese, since the operators of the server could be located anywhere in the world and control the server remotely. The company said that the attack probably began on August 18 and that customer information was exposed for almost a month. Japan Airlines said that there is no evidence of credit card information being leaked and that so far, no reports of malicious transactions have been made.
Stealing “airline miles” may seem like a low-profit business, but for cybercriminals it is. They can sell the miles to other travelers, who can buy airline tickets at lower prices. With “airline miles,” some airlines offer free flights to various destinations around the world. However, the easiest way to turn “miles” into cash is to sell them through brokerage services created specifically for this purpose.
The attack was likely carried out through emails containing malicious attachments. Japan Airlines reported the incident to Tokyo police and is working to repair the damage.

