Pilot Credentials breach exposed data on American and Southwest pilot applicants

Organization
Pilot Credentials
Exploit
Hacking
Industry
Recruitment Technology

Pilot Credentials, an Austin, Texas company that ran recruitment portals for airlines, was breached on or around April 30, 2023. American Airlines and Southwest Airlines said they were notified of the intrusion on May 3 and began writing to affected applicants in late June.

The two carriers' breach filings put the total at 8,754 people: 5,745 pilot and cadet applicants to American Airlines and 3,009 to Southwest. The stolen files included names, dates of birth, Social Security numbers, passport numbers, driver's license numbers, Airman Certificate numbers and other government-issued identification numbers.

Both airlines said their own networks and systems were not involved and that the exposure was limited to data held by the vendor. American added that no customer data was affected. Neither carrier reported evidence that the stolen information had been used for fraud or identity theft.

American and Southwest stopped using Pilot Credentials and moved pilot recruitment onto portals they manage themselves. Each offered affected applicants two years of identity theft protection, American through Experian and Southwest through Equifax, and both said they had contacted law enforcement. Pilot Credentials did not answer questions from reporters about how the attacker got in or whether other airlines using its platform were affected.

Sources