Easyjet hacked: 9 million people's data accessed plus 2,200 folks' credit card details grabbed
- Reference: 1589891553
- News link: https://www.theregister.co.uk/2020/05/19/easyjet_hack_9million_2000_credit_cards/
- Source link:
Some information about the attack was released to the [1]London Stock Exchange by the company, which claimed it had been targeted by "a highly sophisticated source".
Email addresses and "travel details" of "approximately 9 million customers" were slurped by the unidentified hackers. Easyjet insists that the passport and credit card details of nearly all of those people were not affected.
However, 2,208 unlucky souls within the group did have their credit card details nabbed. Precisely which details – 16 digit card number, 3-digit CVV from the reverse, expiry date and so on – were not spelled out.
Twitter activity dating back to the first few days of April, however, shows Easyjet customers asking the airline whether notification emails were real:
[2]@easyJet just had an email detailing a possible incident regarding the hacking of your systems and possible security breach, including card details, can you confirm if this is a genuine email? thanks — JohnnyB (@JohnPaulBentley) [3]April 2, 2020
[4]@easyJet please can someone DM regarding me cancelling my holiday and this security breach, not leaving this another seven days with no response? [5]pic.twitter.com/b2rHcQQcU2 — Samantha Burt (@SamBurt04) [6]April 2, 2020
The latter tweet shows a screen of what appears to be an Easyjet email explaining that “name, travel destination, email address, and credit cards details [sic]” were accessed in the hack earlier this year.
People who think they might have been affected could do worse than change online passwords used for Easyjet services, as well as changing the same password that they’ve used on other websites. Keeping a close eye on online banking activity for any unusual transactions is also wise.
The Register has asked Easyjet for more information and will update this article when the company responds.
"As soon as we became aware of the attack, we took immediate steps to respond to and manage the incident and engaged leading forensic experts to investigate the issue. We also notified the National Cyber Security Centre and the ICO. We have closed off this unauthorised access," said the airline in its statement.
Chief exec Johan Lundgren apologised for the failings of his airline's "robust security measures," saying: "We would like to apologise to those customers who have been affected by this incident."
He added that "on the recommendation of the ICO, we are communicating with the approximately 9 million customers whose travel details were accessed to advise them of protective steps to minimise any risk of potential phishing," saying the unlucky 9 million would be contacted by 26 May.
Professor Alan Woodward of the University of Surrey speculated about the digital break-in: "So either credit card details [were] not encrypted or it's Magecart again. Can't see why they'd leave only 2,000 cards unencrypted, so suggests Magecart."
Jake Moore of infosec biz Eset warned customers to take it seriously: "The biggest problem for EasyJet now is to get this information out to all their customers and make them safe. When the security notification first pops up in an email, the procrastinators out there will stick their heads back in the sand. However, when something like this occurs, the truth is that money can be stolen and large amounts too."
Easyjet has been going through a torrid time, with the novel coronavirus forcing it to shut down flying operations completely as of 16 April. On top of that, founder and blocking minority shareholder Sir Stelios Haji-Ioannou has been engaged in a public campaign to [7]stop its purchase of a new airliner from Franco-German manufacturer Airbus.
That campaign is due to come to a head at a corporate extraordinary general meeting this Friday, 22 May. Doubtless the news of the hack will energise Stelios even more in his campaign to unseat key current executives. ®
Updated at 13:50 on 19 May to add:
The Information Commissioner’s Office said in a prepared statement that it has “a live investigation into the cyber attack involving easyJet” but did not answer questions about when Easyjet notified it of the hack. The agency has previously said it will not be enforcing data protection or freedom of information laws during the coronavirus pandemic, something [8]noticed by Wired magazine today .
[1] https://www.londonstockexchange.com/exchange/news/market-news/market-news-detail/EZJ/14545747.html
[2] https://twitter.com/easyJet?ref_src=twsrc%5Etfw
[3] https://twitter.com/JohnPaulBentley/status/1245668503534874625?ref_src=twsrc%5Etfw
[4] https://twitter.com/easyJet?ref_src=twsrc%5Etfw
[5] https://t.co/b2rHcQQcU2
[6] https://twitter.com/SamBurt04/status/1245676713905881088?ref_src=twsrc%5Etfw
[7] https://www.theguardian.com/business/2020/may/16/easyjet-stelios-haji-ioannou-creates-atmosphere-forced-meeting
[8] https://www.wired.co.uk/article/ico-data-protection-coronavirus
Re: Highly sophisticated
Not to mention apologising for their "robust security measures,"
Re: Highly sophisticated
I can even schpell it when I'm shober!
Re: Highly sophisticated
A 'highly sophisticated' attack in their parlance would be something like:
for ((i=0; i<=9999999; i++)); do wget https://easyjet.com/customerPortal/creditCardDetails?customerId=$i; done
Re: Highly sophisticated
I suspect the people who "hacked" them were not quite up to the sophistication of using a loop - they probably still did it manually.
Or in Basic.
Re: Highly sophisticated
Yeah, that's my normal thinking. "Sophisticated" is code word for "they were smarter than we were". Doesn't say at an absolute level how smart either side was... It's spin from the corporate types to avoid making themselves look incompetent.
Re: Highly sophisticated
It's spin from the corporate types to avoid making themselves think they look incompetent.
FTFY
To the rest of us things look a bit different.
Re: Highly sophisticated
They went further and didn't claim the attack was sophisticated just that the attacker was sophisticated. That is quite some claim - do they know the attacker?
The fact that they "have now closed off the unauthorised source" makes is sound like it is totally not sophisticated at all. Either they've closed off a backdoor, a bug etc or they've removed access to a previous employee. None of which is that sophisticated.
Re: Highly sophisticated
Wasn't the TalkTalk attack originally 'highly-sophisticated' - before it was revealed it was some script kiddies playing with freely-available tools on an unsecured Tiscali database?
Still, it's not like the then-management of TalkTalk are doing anything vital these days are they?
https://www.gov.uk/government/news/new-chair-of-coronavirus-test-and-trace-programme-appointed
Never store CC details
This is why it is never a good idea to store your card details on any website. Never have done, never will.
Also, in unrelated news, the website password is limited to only 20 characters
Re: Never store CC details
I hate max characters in passwords, it bloody annoying pasting in from my password manager of choice to be told the password can't be used!
Re: Never store CC details
Even worse when the "clever" website programmers prevent pasting into fields.
Re: Never store CC details
Or the even stupider ones who use a different set of rules for registration than they do for logging in.
Re: Never store CC details
It's even more annoying when your password manager's formula falls foul of a site's rules (e.g. no non-alphabetic characters etc.) that they couldn't be arsed to tell you about beforehand.
Re: Never store CC details
My work credit card supplier has a limit of nine with only letters and numbers allowed... It's also the card with the highest credit limit that I have.
Re: Never store CC details
And that "max 20 chars password" must not contain "special symbols" such as "&" or "*" !!?!!
Just logged in to change my password but can't see where (or if) any Credit Card info is associated with the account
Re: Never store CC details
"...it is never a good idea to store your card details on any website"
Doesn't make any difference. Either these details were slurped in real-time by a script on the transaction page or they were read from the database. Regardless of whether you "store your card details" on a website or not. They will be recorded as part of the transaction unless they are using a third party provider's system (which can also cause issues). Therefore they either need to two-way encrypt the card details and never store the CCV or never store the card details after the transaction has completed and then not have an easy way to securely do refunds. As a punter you won't know what they do with your card details after you have entered them and clicked submit.
Re: Never store CC details
For refunds the common sense approach would be to only store the last 4 digits and get the customer to confirm the rest when processing the refund.
Re: Never store CC details
Doesn't make any difference.
I'm pretty sure you are correct for actual purchases. I'm unsure how the vendor could handle a chargeback or refund without having the CC number stashed with the transaction data. Likewise monthly subscriptions for services. The alternative to a stored CC for those would appear to be direct charges to your bank account. Somehow, that sounds even worse to me.
But I think the OP was referring to vendors like Amazon who allow one to use a stored credit card number so one doesn't have to type it in every time they order a box of chocolates.
I kind of wonder if it isn't about time for governments to start working on a set of explicit worldwide standards and conventions for digital commerce. Of course there might be a problem if it turns out that no set of standards and conventions that actually allows commerce and is also secure is possible.
Re: Never store CC details
"As a punter you won't know what they do with your card details after you have entered them and clicked submit."
Perhaps it's time sites were legally obliged to tell punters what they do.
Re: Never store CC details
This is why it is never a good idea to store your card details on any website. Never have done, never will.
They're welcome to my vcard ones - the details change after every transaction :).
The only issue is is that it has become such a habit that I forget it's not very useful for subscriptions. Sorry, Akeeba :).
I wonder just how many times the NCSC face-palms when they learn the details of what "a highly sophisticated source" did to get the data.
And just how necessary is it to store credit card data anyway? I know /we/ don't and we do take such payments.
Other reports are saying they became aware of this in January
Its now May. What gives?
Re: Other reports are saying they became aware of this in January
>What gives?
Lazy security. It's the gift that keeps on giving.
Re: Other reports are saying they became aware of this in January
You will find that it is not be that the Security Team being "lazy",
What you will find that the Management has chosen not to implement certain Security controls in for "Business Reasons" even though the Security Team has demanded it.
You will find that the Business will have a high turnover of Security Team as people join, try and do their best to secure the Business, then realise that the Management are not on board.
Re: Other reports are saying they became aware of this in January
What gives? A big fine I should hope. Either that or 72 hours has a different meaning at Easyjet.
from Franco-German manufacturer Airbus??
Really Il Reg?
If it was funny, I wouldn't mind..... but its neither accurate or funny ..... so do please try again?
Its headquarters, are in the Netherlands, the three largest countries involved are France, Spain and Germany, followed by UK and many other European countries ..... so maybe try something like "Euro-Bloc Flying Fortress" etc ......?
There, that wasn't so hard now was it? ;-)
An exemplary response
"As soon as we became aware of the attack, we took immediate steps to respond to and manage the incident and engaged leading forensic experts to investigate the issue."
I'm amazed they responded like this - must have taken some serious thinking to plan for.
We took immediate steps to respond to and manage the incident
"We took immediate steps to respond"
Yup, we sent out some emails and also contacted people than can do nothing.
"manage the incident "
In other words we did our best to avoid GDPR fines.
What we did NOT do was secure our data in the first place... and once the data is gone, it's gone, and soon to be for sale on the Dark Web....
Re: We took immediate steps to respond to and manage the incident
"In other words we did our best to avoid GDPR fines."
Their best might not be good enough if they became aware in January and only notified credit car holders in April.
No mention of it on their website.
I just logged on to change my password, I've not had an email saying I my details were part of the leak but it seems like something I should do.
No sign of any information about this on their website yet or even an automatic prompt to change my password.
Did they use Stevie Wonder for their PCI-DSS audit?
Sheesh, here we go again, another big name scrimping on IT security and using Stevie Wonder for their PCI-DSS audits.
Sod the ICO/GDPR fines, the banks should just take away their ability to take card payments, its not like this stuff is actually difficult.
If it's SQL injection again they really need to rethink their application and DB tiering, but I'll hazard a guess that everything is running on a single Internet-facing tier.
I'd call them cowboys, but at least cowboys wear boots.
OK, hands up ..
Who here allows credit card details to be stored server-side, "for future purchases"?
Re: OK, hands up ..
Done properly storing credit card details isn't a problem since the actual details themselves are never stored just a reference token that can only be used by that one merchant. Of course as an end user you have no idea if the website is going to do it properly or just chuck them into a table next to your email address and password.
As mentioned in the article this most likely isn't Easyjet storing card details but some kind of script running on top of the website harvesting the card details as they are entered. It makes little sense that Easyjet would have card details stored in an accessible way for 2200 people only.
Re: OK, hands up ..
Right now I'm coding the card-taking bit of a site I'm developing and no bloody way, my non-technical business partner wanted us to handle it all in-house to reduce transaction costs but I refused to. No way I'm being responsible for that sort of stuff.
We're using a proper/expensive card processing company, storing nothing card-related for one-off payments and only storing a token to re-identify customers for repeat subscription charges, and I'm being super-paranoid about that, Azure Key Vault for the db connection string and authentication key for the card processor, proofs against sql injection of course, custom obfuscation of the tokens and key itself (because why not), super-locked down privileges about which users can initiate financial stuff (not the ones used by interactive sessions for a start, not even admin users!) and I'm still looking around to see what else I can do.
The idea of leaking people's names and emails is scary enough, even for our small user-base, but card data; jeez, that's terrifying.
@ChrisCoderChap -- Re: OK, hands up ..
Kudos to you, sir - - - - >
Nice to see that there are web developers that have a sense of propriety, scope and sensibility. If only you weren't in the minority...
Re: OK, hands up ..
The main website uses tokenisation of Credit Card details.
If it wasn't then all customers details would have gone, this is most likely some 3rd party site which provides a service to EasyJet. Although it is still EasyJet who is responsible.
I predict the ICO will announce with great fanfare that they've fined EasyJet hundreds of millions of pounds.
Then, years later, you'll find they repeatedly deferred enforcement, eventually settling for 5000 in 2027.
Easyjet would probably [1]only offer them vouchers anyway...
[1] https://www.easyjet.com/en/refund-form
"The Information Commissioner’s Office said in a prepared statement that it has “a live investigation into the cyber attack involving easyJet” but did not answer questions about when Easyjet notified it of the hack. The agency has previously said it will not be enforcing data protection or freedom of information laws during the coronavirus pandemic, something noticed by Wired magazine today."
Wait, what?!?
The agency has previously said it will not be enforcing data protection or freedom of information laws during the coronavirus pandemic
WTF!
That's a first!
So it is earier getting data and creadit card details from EasyJet than getting a refund on a cancelled flight!
Was due to go to Krakow in March but as Poland shut the airport EasyJet cancelled the flights. Got a refund for the flight out - but the flight back has been deleted from my bookings making the task of applying for a refund a tad difficult. Trying the creditcard route but they are similarly in being un-cooperative.
CVV should never be held
The PCI DSS security standard for handling credit cards mandates this. If easyJet (subs note sp) were doing so (about as unlikely as storing their site password in clear text), they'll be in a world of trouble. The standard also requires all CC data to be strongly encrypted.
Re: CVV should never be held
The PCI DSS security standard for handling credit cards mandates this. If easyJet (subs note sp) were doing so (about as unlikely as storing their site password in clear text), they'll be in a world of trouble. The standard also requires all CC data to be strongly encrypted.
Flaws in encryption are almost always around key management. Encrypting a block of data is just a library function call, but key management is a tricky design problem fraught with potential difficulties.
Highly sophisticated
Incompetent data controllers often claim to be victims of "highly sophisticated" attacks, despite taking security "extremely seriously".
An unkind person might suggest that many don't think much about whether a database is private / don't check incoming messages against buffer sizes / never heard of SQL injection. To them, I suppose, any attack is "highly sophisticated".