News: 1590170794

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

It wasn't just a few credit cards: Entire travel itineraries were stolen by hackers, Easyjet now tells victims

(2020/05/22)


Victims of the Easyjet hack are now being told their entire travel itineraries were accessed by hackers who helped themselves to nine million people’s personal details stored by the budget airline.

As [1]reported earlier this week , the data was stolen from the airline between October 2019 and January this year. Easyjet kept quiet about the hack until mid-May, though around 2,200 people whose credit card details were stolen during the cyber-raid were told of this in early April, months after the attack.

Today emails from the company began arriving with customers. One seen by The Register read:

Our investigation found that your name, email address, and travel details were accessed for the easyJet flights or easyJet holidays you booked between 17th October 2019 and 4th March 2020. Your passport and credit card details were not accessed, however information including where you were travelling from and to, your departure date, booking reference number, the booking date and the value of the booking were accessed.

We are very sorry this has happened.

It also warned victims to be on their guard against phishing attacks by miscreants using the stolen records, especially if any “unsolicited communications” arrived appearing to be from Easyjet or its package holidays arm.

Perhaps to avoid spam filters triggered by too many links, the message mentioned, but did not link to, a [2]blog post from the Information Commissioner's Office titled, “Stay one step ahead of the scammers,” as well as [3]one from the National Cyber Security Centre, published last year, headed: “Phishing attacks: dealing with suspicious emails and messages.”

There was no mention in the message to customers of compensation being paid as a result of the hack. Neither, when El Reg asked earlier this week, did Easyjet address the question of compo or credit monitoring services.

More woes, as Easyjet founder flounders

Separately, an Easyjet company general meeting held this morning to sack its CEO and key execs ended with company founder Stelios Haji-Ioannou being outvoted by his shareholders.

UK privacy watchdog threatens British Airways with 747-sized fine for massive personal data blurt [4]READ MORE

Stelios wanted to replace them with people who would cancel a £4.5bn order for new Airbus aircraft, which he says is unnecessary spending at a critical moment. No new details about the hack were mentioned in news reports of the meeting.

Stelios did not take news of his loss well, issuing a [5]statement [PDF] accusing Easyjet and Airbus of “voting fraud,” threatening to sue the Daily Telegraph for pouring scorn on his anti-Airbus campaign, and branding Airbus itself “the scoundrels”.

The Guardian [6]reported Easyjet finance chief John Barton as saying: “The company has no right to unilaterally terminate the contract [with Airbus].

"The one-off costs associated with termination would be very material and taken with the future value of contract, termination would be hugely detrimental and seriously impact the company’s ability to operate as a low-cost airline.”

Easyjet's fleet has an average age, according to a planespotters' [7]website , of just over eight years – relatively young in aviation terms – though some of its longest-serving aircraft are more than 15 years old. ®



[1] https://www.theregister.co.uk/2020/05/19/easyjet_hack_9million_2000_credit_cards/

[2] https://ico.org.uk/your-data-matters/your-data-matters-blog/

[3] https://www.ncsc.gov.uk/guidance/suspicious-email-actions

[4] https://www.theregister.co.uk/2019/07/08/ico_threatens_ba_with_huge_fine_for_huge_data_loss/

[5] https://easy.com/pdf/2020-05-22-stelios-and-easygroup-on-easyjet-voting-fraud-by-airbus-22-may-20-at-1220h-bst-post-vote-count.pdf

[6] https://www.theguardian.com/business/2020/may/22/easyjet-founder-stelios-fails-in-attempt-to-oust-chairman-and-ceo

[7] https://www.planespotters.net/airline/easyJet

O RLY

Maybe easyJet don't need to continue as a business. Certainly the current travel culture will crank "survival of the fittest" up to 11 and easyJet seem anything but fit. It's hard to mourn a company, one of many, that doesn't take security seriously.

Yet Another Anonymous coward

So we have flag carriers bailed out by their governments and all the cheap airlines go bust and we go back to paying £500 on 'British' Airways to fly to europe

Stelios & EGM

Steve Foster

This isn't the first time Stelios has forced an EGM to be held, as he does like to throw tantrums from time to time. He basically thinks he always knows better than the EasyJet board - sometimes he might be right, but trying to throw his weight [vis his large shareholding] around like this just makes him look petty and vindictive.

DPA 2018?

Mike Richards

So, when did EasyJet inform the ICO?

From memory, under the DPA 2018 they have 72 hours to refer themselves after discovering the breach which doesn’t seem to fit with an announcement this week of a hack that occurred a couple of months ago and which left customers vulnerable to fraud.

We are very sorry this has happened.

Anonymous Coward

says Michael O'Leary, this (...) (...)

Re: We are very sorry this has happened.

Overflowing Stack

Michael O'Lardy of Brianair "Easyjet want to give your details away, we want you to know we've sold them and you'll have to pay to get them back"

Re: We are very sorry this has happened.

Yet Another Anonymous coward

All Ryanair's customers got leaked int he sports direct hack

Credit Monitoring

IGotOut

Is available for a small upgrade charge.

Your reasoning is excellent -- it's only your basic assumptions that are wrong.