Warning! SpiceJet confirms data breach of 1.2 million passenger details

A security researcher gained access to one of the airline's systems by brute-forcing an easily-guessable password.

Update: 2020-01-31 01:40 GMT
A SpiceJet flight slid off the runway during landing at Mumbai's international airport on September 19.

India's privately-owned airline SpiceJet has confirmed data breach of over a million of its passengers after a security researcher highlighted a security lapse in its systems.

According to TechCrunch, a security researcher, who described their actions as 'ethical hacking', gained access to one of the airline's systems by brute-forcing an easily-guessable password.

The database backup file on the system was unencrypted, allowing access to private information of more than 1.2 million passengers last month. The details included flight information and details of each passenger, including their name, phone number, email address, and date of birth.

The researcher had alerted SpiceJet about the database, but it was only after they informed government-run cybercrime agency CERT-In that the airline took necessary steps to protect its user database.

Tags:    

Similar News