Skyticket hit by unauthorized access, data on 14.64 million customers may have leaked

ロイター··JP·Read original
3▲0 ▼1Impact / 5
Summary · why it matters

Online travel agency Adventure announced on the 9th that its comparison and booking site skyticket suffered unauthorized access by a third party, and that data on approximately 14.64 million customers may have been leaked externally. The unauthorized access occurred separately in the company's servers, its business management system, and reservation data for its bus booking service. Between October 2 and 4, some of skyticket's administrative functions were exploited to gain unauthorized access to data on other servers and in the cloud, leaking information including names, dates of birth, email addresses, phone numbers, addresses, and hashed login passwords. In the unauthorized access to the business management system that occurred on September 20, refund account information may have leaked, and unauthorized login to one member's account has also been confirmed. The company has blocked the routes used for the unauthorized access and says no credit card numbers or passport information were leaked. The impact on its business results is currently being examined, and the company is urging customers to change their passwords.

Impact on assets 1

Information Technology▼
Adventure, Inc.
6030
▼ NegativeRegulationrelevance

Skyticket suffered unauthorized access leaking data on ~14.64 million customers, prompting a security breach investigation and password-change advisory.