Dunghill Leak claimed a 1.3TB data theft from travel technology firm Sabre

Organization
Sabre Corporation
Exploit
Ransomware
Industry
Travel Technology

Sabre Corporation, the travel technology company whose systems underpin airline and hotel reservations for carriers and chains worldwide, said in September 2023 that it was investigating claims of a large data theft by an extortion group.

The Dunghill Leak group, which researchers link to the earlier Dark Angels ransomware operation, listed Sabre on its dark web leak site and said it had taken about 1.3 terabytes of files. Its posts described databases covering ticket sales and passenger turnover, employee personal data and corporate financial information. TechCrunch reported that the accompanying screenshots showed database names holding tens of millions of booking and billing records, along with employee files containing work locations, passport numbers, visa details and I-9 employment authorization forms.

Sabre did not confirm the volume or the contents. A spokesperson said the company was "aware of the claims of a data exfiltration made by the threat group, and we are currently investigating to determine their validity."

The date of the intrusion was not established publicly. TechCrunch reported that some of the material in the screenshots appeared to date from as recently as July 2022 and that the breach date remained unknown. Legal commentators noted at the time that Sabre would issue individual breach notification letters if the investigation confirmed that personal data had been taken.

Updates

  1. Sabre notified 29,590 people and placed the intrusion in July 2022, more than a year before it was discovered in September 2023. It said the stolen data included Social Security numbers, dates of birth, financial account numbers, passports, driver's licences and signatures, and offered 24 months of Experian IdentityWorks.

Sources