Back to the archive

The encyclopedia · Advertising & PR · Marketing decision · 2018

Cathay Pacific sat on a breach affecting 9.4 million passengers for five months

Cathay found hackers had reached passenger data in March 2018 but waited until October to say so. Lawmakers called the delay a cover-up; the airline denied it.

Cathay Pacific · 2018-10

What happened

In March 2018, Cathay Pacific, Hong Kong's flagship airline, noticed suspicious activity on its network. By early May it had confirmed that hackers had accessed passengers' personal data. It did not tell the public. Not until 24 October 2018 did the airline announce that the personal data of up to 9.4 million passengers had been accessed — passport numbers, identity card numbers, travel history, email addresses and expired credit card details. No passwords, it said, had been taken.

Chief executive Rupert Hogg apologised, saying the airline was 'very sorry for any concern this data security event may cause our passengers,' and insisted there was 'no evidence that any personal data has been misused.' He said Cathay had acted immediately to contain the breach and investigate. What it had not done was tell anyone for roughly five months — and that silence, more than the hack itself, became the story.

On 14 November, Hogg and chairman John Slosar were summoned before Hong Kong's Legislative Council to explain the delay. Lawmakers called it a 'blatant attempt' to cover up the breach, depriving passengers of months to protect themselves. Slosar insisted 'there was never any attempt to cover anything up' and called it 'one of the most serious crises that our airline has ever faced.' Hogg said the airline 'did regret the length of time' and 'would do it a different way tomorrow.' The denial, paired with a five-month delay, did little to restore trust.

Why it happened

  • The airline treated disclosure as something to release only once it had full answers, while passengers and regulators treated a known breach as something to be told about immediately.
  • Waiting five months meant the apology arrived alongside the question 'what else did you sit on?', so the response had to fight the delay rather than the breach.
  • Denying a cover-up to a legislature that had already called the delay one made the airline sound like it was arguing with the victims rather than answering them.
What it cost9.4M passengers exposed; legislature summons; trust hitcostly

The lesson

In a breach, the clock is part of the crisis. Every week you wait to disclose reads as concealment, not diligence — and by the time you apologise, you are answering for the silence, not the hack.

Aftermath

Cathay said it had contained the breach, brought in a cybersecurity firm, and strengthened its IT security, and it promised to 'report instantly' if it happened again. The airline later faced regulatory scrutiny over the incident. For companies handling customer data, the case became a standard warning that the response to a breach is judged on a stopwatch: a fast, honest disclosure contains the story, while a slow one turns an incident into an accusation — and an apology into a defence.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →