Back to the archive

The encyclopedia · Software & IT · Technical decision · 2021

Air India's passenger service system is breached, exposing 4.5 million travellers

A hack of the SITA passenger system let attackers roam for weeks and took passport and credit-card data for about 4.5 million Air India passengers.

Air India · 2021-05-21

What happened

In 2021, Air India revealed that a cyberattack on its passenger service system, operated by third-party IT provider SITA, had exposed the personal data of about 4.5 million passengers worldwide. The compromised information, covering records registered between August 2011 and February 2021, included names, dates of birth, contact details, passport information, ticket data, and frequent-flyer records, along with credit-card data.

The breach was not brief. SITA and Air India said the attackers had access for roughly three weeks in February 2021, and Air India did not confirm the exposure publicly until May 2021, several months after it first learned of the incident. SITA notified Air India in late February, and the details of affected data subjects were only provided in late March and early April.

The attack was a shared-infrastructure failure. SITA's passenger service system is used by many airlines, and the breach of Air India's data was part of a wider compromise of the SITA platform — a single point of failure for the carriers that relied on it. Air India's statement emphasised that its own systems were not directly attacked, but the data was lost anyway because it lived in a third party's system.

The decision issue is one of dependency and disclosure. Air India entrusted the handling of highly sensitive passenger data to a third party whose system was compromised, and it took months to tell affected passengers that their passport and credit-card information had been accessed. The multi-week access window and the delayed disclosure both compounded the harm.

Why it happened

  • A cyberattack on SITA's passenger service system exposed the data of about 4.5 million Air India passengers
  • Attackers had access for roughly three weeks in February 2021, and the breach was not publicly confirmed until May
  • Sensitive data including passport numbers and credit-card information was compromised
  • Air India relied on a third-party system to hold customer data, and a breach of that shared platform took months to disclose
What it cost~4.5M passengers' passport + credit-card data exposedcostly

The lesson

Passenger data does not stop being sensitive because a third party holds it: Air India lost the passport and card data of 4.5 million travellers through a SITA breach it did not disclose for months.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →