Air Europa told customers passport and ID data was exposed in 2023 breach
- Organization
- Air Europa
- Exploit
- Hacking
- Industry
- Airline
Air Europa, Spain's third largest airline, notified customers on March 21, 2024 that additional personal data may have been exposed as a result of a cyberattack the carrier first disclosed in October 2023.
The original incident affected the airline's online payment system. Air Europa told customers at the time that card numbers, expiry dates and CVV security codes had been compromised, and advised them to cancel the affected cards to prevent fraudulent charges.
Follow up technical analysis widened the picture. In its March 2024 communication, the airline said the data that may have been leaked included names and surnames, ID card or passport numbers, frequent flyer codes, postal addresses, dates of birth, telephone numbers, email addresses and nationality. Air Europa said it had no indication that the information had been used fraudulently and that any resulting inconvenience would be limited.
The airline did not disclose how many customers were affected. It said it had reported the incident to the authorities, notified those concerned, and was continuing an ongoing programme of security improvements. International Consolidated Airlines Group, which held a minority stake in Air Europa at the time, said publicly that it would never email the airline's customers directly, a caution aimed at people who might receive fraudulent follow up messages purporting to come from the group.