Live data from Hacker News

EasyJet admits a cyber-attack has affected approximately nine million customers

bbc.co.uk

91–100 of 164 posts

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#91

> EasyJet said it first became aware of the attack in January. vs > The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible. So either EasyJet was delayed in their reporting of the breach, or the ICO didn't feel it was urgent to notify 9 million people that th…

Their official statement says

> we took immediate steps to respond to and manage the incident and engaged leading forensic experts to investigate the issue. We also notified the National Cyber Security Centre and the ICO. We have closed off this unauthorised access.

Maybe the relevant supervising authority didn't find it important to notify those 9 million customers.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#92
post #64

The number one reason I do not keep CC info, and why I don't fill out details wherever I can. I don't trust your security.

good luck buying a plane ticket from easyjet without giving them your CC info

Some banks can generate a virtual CC ad-hoc, so you could have different CC details per each transaction. It's rare, I wish my bank did it, but it exists.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#93

Could be catastrophic, as I have my ID details saved there for quick checkin.

Me too, could be a lot of passports being cancelled and reissued shortly

Why would you need to cancel and reissue any passports? At worst the hackers might have stolen some passport numbers and expiry dates. What exactly could they do with those that would warrant issuing an entirely new passport?

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#94
post #61

Earlier quoted context omitted.

Someone could hack themselves constantly and get paid to do it

And risk going to prison for a long time.

Pointing out unintended consequences. The rule suggested would tend to increase, however slightly, crimes commmitted.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#95
post #50
post #33

Earlier quoted context omitted.

Partner had trouble doing an online check-in with EasyJet. Some kind of error. Arrived at the airport to be told that even though she has the ticket, she does not have a place. There were ~5 people with her in the same situation. 4 other people did not show up for the flight, so some of them got a seat after all. My partner did not, spent the night in the airport. Took about a year and loads of calling to get a compe…

Overbooking is actually incredibly common. Every flight has some number of passengers not show up. Airlines prefer to compensate one or two people for the fact that they didn't get a seat, instead of leaving some number of seats empty. Getting compensated should be practically instant though, and definitely not take a year, so something went terribly wrong there.

> so something went terribly wrong there.

Not really.

Even if you're legally entitled to compensation Easy Jet is famous to let you jump through so many hoops, lie to you, hang you out to dry, let you wait forever until you just give up.

Outsourcing to some company like Airhelp (which, charges 35% of recovered compensation if successful) may be a viable option to just save you the headache, while sticking it to the carrier trying to stiff you.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#96
post #61

Time for datapoint tax, which will reimburse victims of these crimes

Someone could hack themselves constantly and get paid to do it

Yes, there are many criminal ways to make money. It would be nothing new. For example, burning your house or failing business down to make a claim is probably as old as insurance.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#99
post #68

I just logged in to change my easyJet password: > Your password must be a single word between 6 and 20 characters in length and must not include the special characters # & + or space. Come on! This is ridiculous. If you're going to get hacked at least have a sane password policy.

Still better than my bank (one of Spain's biggest) that requires your password to be 8 (not less, not more) digits.

Use "password" - eight letters and it's English and so should be safe on a Spanish site.

Re: EasyJet admits a cyber-attack has affected approximately nine million customers

#100
post #68

I just logged in to change my easyJet password: > Your password must be a single word between 6 and 20 characters in length and must not include the special characters # & + or space. Come on! This is ridiculous. If you're going to get hacked at least have a sane password policy.

Still better than my bank (one of Spain's biggest) that requires your password to be 8 (not less, not more) digits.

HSBC in France have the same, it's a huge motivator for me to switch away.
Post reply on HN