SpiceJet data breach affects 1.2 million passengers


New Delhi, Jan 31 (IANS): A data breach has hit one of India's largest privately-held carriers, SpiceJet, affecting 1.2 million passengers in the country.

Security researchers who first revealed the data breach told TechCrunch that they gained access to the carrier's systems by brute-forcing the system's easily guessable password.

In a statement, SpiceJet said: "At SpiceJet, safety and security of our fliers' data is sacrosanct. Our systems are fully capable and always up to date to secure the fliers' data which is a continuous process. We undertake every possible measure to safeguard and protect this data and ensure that the privacy is maintained at the highest and safest level".

The private information of more than 1.2 million passengers were contained on an unencrypted database backup file of SpiceJet's systems, according to the report.

The details that the security researchers got access to as part of what they described as their "ethical hacking" efforts included the passenger's name, their phone number, email address and their date of birth.

Acording to the security researchers, the database was easily accessible to everyone who knew where to look.

Despite alerting SpiceJet about the data base, the researchers said they did not receive a meaningful response from the carrier.

This led them to alert the Indian Computer Emergency Response Team (CERT-In).

The aviation major, however, did not confirm CERT-In's findings.

  

Top Stories


Leave a Comment

Title: SpiceJet data breach affects 1.2 million passengers



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.