ThreatLocker

Air Canada Mobile App Users Affected By Data Breach

  • August 29, 2018
  • 11:52 AM
  • 0

Air Canada informed today 20,000 of its mobile app users that information listed under their profile may have been accessed without authorization.

Between August 22-24, the company noticed unusual login activity and responded by stopping the attempts. To protect customer data, Air Canada locked all its 1.7 million mobile app accounts.

Those who want to reactivate their account are advised to follow the instructions on the app the next time they log in.

image

However, people complaining on Twitter about the potential intrusion also complain about not being able to reset their password because the app keeps crashing.

An intruder gaining access to the profile of an Air Canada mobile app user could see at least the owner's name, email address, and telephone number.

Additional data a user may add to their profile includes their number for the  Aeroplan loyalty program, Passport number, NEXUS number, Known Traveler Number, gender, birthdate, nationality, passport expiration date, passport country of issuance and country of residence.

Card data and official documents are safe

In a statement about the breach, Air Canada says that credit card data remains unaffected and that no aircanada.com accounts were affected as they are not connected to the mobile app.

"Credit cards that are saved to your profile are encrypted and stored in compliance with security standards set by the payment card industry or PCI standards," the statement reads.

Those worried about their passport information should know that the risk of falling victim to identity theft is low.

According to the Canadian government website, the information available in a passport is not sufficient to issue the document to another person. Additional identification is necessary to confirm the personal details.

As an added precaution, Air Canada recommends its customers to regularly review their financial transactions and contact their financial service provider if they notice any unusual activity in their bank account.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper
Ionut Ilascu
Ionut Ilascu is a technology writer with a focus on all things cybersecurity. The topics he writes about include malware, vulnerabilities, exploits and security defenses, as well as research and innovation in information security. His work has been published by Bitdefender, Netgear, The Security Ledger and Softpedia.
Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Login

Reporter

Help us understand the problem. What is going on with this comment?

Read our posting guidelinese to learn what content is prohibited.

SUBMIT