Live data from Hacker News

EasyJet admits a cyber-attack has affected approximately nine million customers

bbc.co.uk

41–50 of 164 posts

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#42

Earlier quoted context omitted.

Me too, could be a lot of passports being cancelled and reissued shortly

The question is: who will pay that? It costs around 100 Euro to renew a passport here in Germany.

The individual, as usual. Even if there's some legal recourse the inconvenience and expense will be larger than the payoff. And there's no legal framework to just be compensated by default in such cases.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#44
post #34

EasyJet was the one hacked, the customers got their information stolen from the hack but were not themselves hacked.

This reminds me of "identity theft". Someone didn't steal my identity, someone stole from the bank using my identity. It should really be called "bank fraud".

A great sketch about this https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#45

Having worked with EJ I just wanted to point out their system are insanely fragile. They never notified us about breaking changes and the system itself would go down multiple times. There was no CS when something goes wrong. And this was their B2B api. And from talking to ppl who were working in EJ a lot of things were being done on excel spreadsheets and emailed across. Just wanted to give this info as a sort of ref…

Interesting to hear, although a lot of companies still rely on emailing documents to each other. A few years ago I interviewed with a consultancy that provided a lot of development work for easyJet. They were operating under an old model of both work organisation and technology and not very keen to change. Interview went OK until I met the company CTO, who's personality left a lot to be desired. We ended up having a heated discussion about the need to innovate, or not in his case. Unsurprisingly, I never heard back from them.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#46
post #2

But they didn't reveal any details about it. They just told it was a highly sophisticated cyberattack. Guess?

"highly sophisticated cyberattack" is just PR speak for "cyberattack" - and successful cyberattacks are far more likely to be the result of negligence from company holding the data than the sophistication of the attackers.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#47

Interesting. Were they storing/operating unsalted plaintext credit card info? I hope not.

Only a couple thousand had their Credit Card details stolen whereas nine million had information stolen. This sounds like they were able to access the database to steal customer information and plant code on the website to scrape any future transactions before the Credit Card information is encrypted in the database.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#48

Earlier quoted context omitted.

Why would reissuing passports help? The old passport is still valid and only the government is actually able to tell whether it's cancelled (as they have access to the passport DB), but for all other intents and purposes (identity verification for banks, etc) the other passport still appears perfectly valid.

Stolen and lost documents are logged in an international data base. I have lost my ID a few years ago. Every now and then I am being asked at borders whether I have found it or it was still lost. Banks check during the KYC process whether the document ID is on this blacklist. If yes, authorities are contacted. Hence, once compromised/lost, apply for a new one and tell them what happened with your old one.

In my experience IDs are checked very informally by most companies such as utilities, etc. GDPR access requests usually require a proof of identity and I very much doubt they are checked beyond the details on them matching the account so it can be yet another vector for stealing more data based on the passport. Banks are probably the only place where they may be checked against s lost/stolen DB but it won't prevent you getting your SIM & phone number taken over because someone impersonated you to your mobile carrier.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#49
post #37

Really tough on an already struggling airline. Wonder if their security team were fully in place recently?

Easyjet have been a main airline within the UK for many many years. They may be struggling because of the current environment but this isn't a small operation who wouldn't have a security team.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#50
post #33
post #3

If EasyJets systems are anything like their customer service, their in-flight food, their baggage handling or their scheduling, this is not surprising.

Partner had trouble doing an online check-in with EasyJet. Some kind of error. Arrived at the airport to be told that even though she has the ticket, she does not have a place. There were ~5 people with her in the same situation. 4 other people did not show up for the flight, so some of them got a seat after all. My partner did not, spent the night in the airport. Took about a year and loads of calling to get a compe…

Overbooking is actually incredibly common. Every flight has some number of passengers not show up. Airlines prefer to compensate one or two people for the fact that they didn't get a seat, instead of leaving some number of seats empty.

Getting compensated should be practically instant though, and definitely not take a year, so something went terribly wrong there.

Post reply on HN