comscore Data of ‘several hundred thousand’ customers exposed, Delta says | Honolulu Star-Advertiser
Business Breaking | Top News

Data of ‘several hundred thousand’ customers exposed, Delta says

Honolulu Star-Advertiser logo
Unlimited access to premium stories for as low as $12.95 /mo.
Get It Now
  • ASSOCIATED PRESS

    A Delta Connection regional jet operated by GoJet Airlines takes off from Logan International Airport in Boston in January.

Delta now says that payment-card information for about “several hundred thousand” airline customers may have been exposed by a malware breach last fall that also hit Sears and other companies.

The airline says that the malware attack may have exposed customers’ names, addresses, credit card numbers, card security codes and expiration dates.

Delta Air Lines Inc. offered the additional details about the attack today, a day after saying that only a “small subset” of customers was affected.

The airline said that it wasn’t sure whether customers’ information was actually compromised by malware that it believes was in software used by (24)7.ai, which provided the airline with online chat services for customers, for about two weeks. The software company said it discovered and fixed the breach in October.

Sears said in a statement that it believes the malware led to “unauthorized access to less than 100,000 of our customers’ credit card information.”

Sears Holdings Corp., which also operates Kmart stores, said it learned of the problem in mid-March and immediately notified credit-card companies to prevent potential fraud. Both Delta and Sears said they worked with federal law enforcement officials and IT-security experts.

It does not appear that the companies’ systems were hacked, said Bill Curtis, chief scientist at CAST, a software-security firm. Rather, the malware targeted customers as they made online purchases using infected software.

Consumers “downloaded something that was watching your screen and waiting for the credit cards to float,” Curtis said. “They stole the data as you entered it.”

A spokesman for (24)7.ai, which is based in San Jose, California, did not immediately respond to a request for comment.

Curtis said (24)7.ai “has a huge liability here.” He said companies that use outside technology providers also must take steps to check the security of the software used by those providers.

Neither Delta nor Sears responded immediately to questions about steps they took to ensure the security of the (24)7.ai software.

Comments (2)

By participating in online discussions you acknowledge that you have agreed to the Terms of Service. An insightful discussion of ideas and viewpoints is encouraged, but comments must be civil and in good taste, with no personal attacks. If your comments are inappropriate, you may be banned from posting. Report comments if you believe they do not follow our guidelines.

Having trouble with comments? Learn more here.

Click here to see our full coverage of the coronavirus outbreak. Submit your coronavirus news tip.

Be the first to know
Get web push notifications from Star-Advertiser when the next breaking story happens — it's FREE! You just need a supported web browser.
Subscribe for this feature

Scroll Up