About 2,000 Dublin Airport staff had pay data taken in the Aon MOVEit breach
- Organization
- daa (Dublin Airport Authority)
- Exploit
- Third-Party Data Breach
- Industry
- Aviation
daa, the operator of Dublin Airport, confirmed on July 3, 2023 that pay and benefits information belonging to roughly 2,000 of its employees had been stolen. The data was not taken from daa's own systems. It was held by Aon, a professional services firm the airport operator had contracted to compile and print personalized total rewards statements for staff.
Aon was one of hundreds of organizations caught by the exploitation of CVE-2023-34362, a vulnerability in Progress Software's MOVEit Transfer file transfer software. Progress disclosed the flaw on May 31, 2023 and released a patch the following day, but the Cl0p ransomware group had already used it to pull data from exposed servers.
daa did not itemize the fields involved beyond saying they related to some employees' pay and benefits. The company said it took the security of sensitive personal information extremely seriously, notified Ireland's Data Protection Commission of the third-party breach, and was offering support, advice and assistance to the employees affected. It stressed that there had been no breach within its own organization.
It was not established at the time whether the stolen daa records were ever published. Other organizations exposed through the same campaign included Aer Lingus, British Airways, the BBC and the pharmacy chain Boots.