Connect with us

Security

Iberia Exposes Customer Data in Vendor Security Breach

Published

on

Recently, Spanish airline giant Iberia disclosed a data security breach that originated from a breach at one of its suppliers.

This revelation comes in the wake of a cyber threat actor’s claim on hacker forums that they have obtained 77 GB of data allegedly taken from the airline.

Details of the Data Breach

Iberia, a prominent airline in Spain and a part of the International Airlines Group (IAG), stated that unauthorized access to a supplier’s systems led to the exposure of specific customer information.

Wiz

According to an email reviewed by threat intelligence platform Hackmanac, the compromised data potentially includes:

  1. Customer’s name and surname
  2. Email address
  3. Loyalty card (Iberia Club) identification number

The airline clarified that customers’ Iberia account login credentials and passwords were not compromised, and no banking or payment card details were accessed.

Iberia notice of security incident emailed to customers (Hackmanac on X)

Iberia’s security notice emphasized their immediate response to the incident, activating security protocols and implementing measures to contain and prevent further breaches.

In response to the breach, Iberia has enhanced security measures for customer email addresses, requiring a verification code for any account modifications.

The airline is actively monitoring its systems for suspicious activities, with authorities notified and investigations ongoing in collaboration with the affected supplier.

The email also urged vigilance against potential fraudulent activities and advised customers to report any suspicious behavior to their call center.

Connection to Previous Data Theft Claims

The disclosure of the breach follows a recent claim by a threat actor who alleged access to 77 GB of data from Iberia, seeking to sell it for a significant sum.

In the online forum post, the threat actor asserted that the data, extracted from the airline’s internal servers, contained technical information and internal documents.

Threat actor claiming to sell purported Iberia data
Threat actor claiming to sell purported Iberia data last week (Hackmanac on X)

While it remains unclear if the leaked data is related to Iberia’s recent incident, the airline attributes the breach to a third-party vendor rather than internal servers.

BleepingComputer has not independently verified the authenticity of the advertised data. Further inquiries have been made to Iberia’s press team for clarification.

Meanwhile, Iberia advises customers and partners to remain cautious of any suspicious messages purportedly from the airline, as they could be phishing attempts.

Wiz

With MCP (Model Context Protocol) emerging as the standard for connecting LLMs to tools and data, security teams are prioritizing measures to ensure the safety of these new services.

Discover 7 best practices in this free cheat sheet that you can implement immediately.

See also  Digital Parasite: The Evolution of Ransomware and its Impact on Residency

Trending