cloud

Over 1.2 Million Passengers Details Exposed in the SpiceJet Data Breach

Security flaw exposed more than 1.2 million Spicejet passengers details, the exposed details include the passenger name, phone number, email address and date of birth.

According to TechCrunch, a security researcher who described their actions as “ethical hacking” gained access to one of the SpiceJet’s systems by using the brute-forcing method.

The system contains an easily guessable password which lets the researcher gained access to the backup database.

The backup database is unencrypted and has the private information of more than 1.2 million passengers of the company.

The database also contains the rolling month’s flight information including the details of each commuter, reads TechCrunch report.

The researcher reached out to SpiceJet, but there is no valid response from them, later he alerted the CERT-In, a government-run agency in India that handles cybersecurity threats.

Later CERT-In, confirms the flaw and alerted SpiceJet to take necessary steps to secure the database.

A SpiceJet spokesperson said that “at SpiceJet, safety and security of our fliers’ data are sacrosanct. Our systems are fully capable and always up to date to secure the fliers’ data which is a continuous process. We undertake every possible measure to safeguard and protect this data and ensure that the privacy is maintained at the highest and safest level.”

SpiceJet is a low-cost and second largest Indian airline, it has a market share of 13.6% as of March 2019. The company operates 630 flights daily.

Also Read

30 Million Credit Data Available for Sale in Dark Web – Wawa Massive Payment Card Breach

Microsoft Data Leak – 250 Million Microsoft Customer Service Support Records Exposed Online

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago