Travel agent leaked customer data by – this is embarrassing - giving it away in a hackathon
- Reference: 1607326388
- News link: https://www.theregister.co.uk/2020/12/07/data_breach_in_hackathon_data/
- Source link:
The event in question was staged by global travel agency outfit The Flight Centre Group, which in March 2017 staged an event called a “design jam” for its Australian operations. The event aimed to “create technological solutions for travel agents to better support customers during the sales process.”
16 teams collectively comprising 90 people signed up and were given access to a dataset containing 106 million rows of data and containing 6,121,565 individual customer records.
Flight Centre thought it had cleaned that dataset so that design jammers could see year of birth, postcode, gender and booking information, but no personal information. And to make sure that was the case, Flight Centre had someone review “a top 1,000 row sample of each Data File within the Dataset”.
But each file was 28 million rows deep and as the design jam participants worked their way into the dataset, one noticed credit card numbers in a free text field.
Go ahead, stage a hackathon. But pray it doesn't work too well [1]READ MORE
To its credit, within 30 minutes of learning about the breach, Flight Centre restricted access to the data to design jam participants. Less responsibly, it restored access but with the free text field restricted to ten characters.
A [2]ruling regarding the incident by Australian Information Commissioner Angelene Falk found that poor design of, and abuse of, the free text field was the culprit. The report was spotted by [3]itnews.com.au
Poor design of the field was in evidence because the free text field did not exclude data such as credit card and passport numbers, despite the existence of policies that instructed workers not to use the field for such purposes. Some workers had clearly not followed that policies.
The result was that 0.025 percent of records in the design jam data contained personal information.
Falk noted that Flight Centre contacted as many of the impacted customers as it was able and volunteered to pay for new passports, conducted credit card fraud monitoring and generally did all it could to make good after the incident. So it got off with being told to tighten up its databases and policies, a tongue-lashing, and being told not to let this happen again or else.
Flight Centre no longer runs hackathons. ®
Get our [4]Tech Resources
[1] https://www.theregister.com/2017/05/23/go_ahead_stage_a_hackathon_but_pray_it_doesnt_work_too_well/
[2] http://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr//2020/57.html
[3] https://www.itnews.com.au/news/flight-centre-hackathon-behind-2017-breach-exposed-6918-customers-data-558644
[4] https://whitepapers.theregister.com/
Postcodes [in the UK] can be personal too
"thought it had cleaned that dataset so that design jammers could see year of birth, postcode, gender and booking information, but no personal information"
I have a UK postcode shared with just two other properties. The year of birth and gender would directly identify me if you knocked all three doors.
Re: Postcodes [in the UK] can be personal too
Postcodes can resolve to a single dwelling. But they aren't private, so...
Re: Postcodes [in the UK] can be personal too
They may not be private, but they can be personal.
Since they can quiet easily link to a person they are seldom used in full when providing so called anonymized data. That's why in the UK only the first section (out-code) should be used in exercises like the one being discussed.
New passports
They volunteered to pay for new passports and credit card fraud monitoring. If only the UK's ICO could be so bold and insist on this in future where my details are leaked. New passports are not cheap.
No longer runs hackathons
Why not? Seems a PI breach was found in quite a safe environment, they then reacted sensibly and quickly.
Would they rather the issue was found by some balckhats later, then compromised for n-years before they found out?
Feels like the same ol' issue well known to test teams that the dev teams don't like to be told of bugs. Before release. Before anyone else finds out. Sigh.
And UK?
Was FCI UK involved in this at all? That might put them on the ICO radar.
Problem is...
Not just free-text fields. Any field can be re-purposed on the fly. If the field is big enough and not validated in any way, expect misuse.