Cathay Pacific fined by UK watchdog over massive data breach

AFP
Hong Kong carrier Cathay Pacific has been fined HK$5 million (US$643,320) by Britain's privacy watchdog over a huge data leak of more than 9 million customers.
AFP
Cathay Pacific fined by UK watchdog over massive data breach
Imaginechina

A jet plane of Cathay Pacific Airways is being towed at the Hong Kong International Airport in Hong Kong, China, on October 28, 2012.

Hong Kong carrier Cathay Pacific has been fined HK$5 million (US$643,320) by Britain's privacy watchdog over a huge data leak of more than 9 million customers including passport numbers and credit card details.

The Information Commissioner's Office said in a statement on Wednesday it has ordered the airline to pay 500,000 pounds for "failing to protect the security of its customers' personal data."

Between October 2014 and May 2019, a lack of security measures on the carrier's computer systems led to a massive data breach involving 9.4 million customers around the world — including 111,578 from the UK — according to the ICO.

"People rightly expect when they provide their personal details to a company that those details will be kept secure to ensure they are protected from any potential harm or fraud," Steve Eckersley, ICO director of investigations, said. "That simply was not the case here."

He added that multiple serious deficiencies they found "fell well below" standard and the airline failed to satisfy four out of five of the National Cyber Security Centre's basic guidance.

The Hong Kong-based airline in October 2018 admitted that about 860,000 passport numbers, 245,000 Hong Kong identity card numbers, 403 expired credit card numbers and 27 credit card numbers with no card verification value were accessed.

Other compromised passenger data included nationalities, dates of birth, phone numbers, e-mails, and physical addresses.


Special Reports

Top