Connect with us

Security

Korean Air Breach: Employee Data Exposed in Massive Security Incident

Published

on

Korean Air Employee Data Breach: What You Need to Know

Recently, Korean Air, one of Korea’s leading airlines, fell victim to a data breach that compromised the personal information of thousands of its employees. The breach occurred after Korean Air Catering & Duty-Free (KC&D), the airline’s in-flight catering supplier and former subsidiary, was hacked.

Korean Air, known for its extensive fleet of over 160 aircraft and annual revenue exceeding $11 billion, issued an internal notice following the breach. The airline has a workforce of over 20,000 employees and serves millions of passengers each year.

The data breach was discovered when KC&D, which separated from Korean Air in 2020 to operate as an independent entity, reported the security incident to the airline. Personal information, including names and bank account numbers, stored in the company’s ERP system on compromised servers was accessed by the hackers.

In response to the breach, Korean Air CEO Woo Kee-hong emphasized the seriousness of the situation and reassured employees that the company is taking necessary steps to address the issue. While the exact number of affected employees was not disclosed, reports suggest that around 30,000 data records were compromised.

Korean Air promptly informed relevant authorities about the breach and advised employees to remain vigilant against potential phishing attempts or fraudulent activities using stolen information. The airline is actively investigating the extent of the breach to prevent further damage.

Although the perpetrators behind the attack have not been identified, the Clop ransomware gang has claimed responsibility for the KC&D incident. The group has a history of targeting various organizations worldwide and leaking stolen data on the dark web.

See also  Exposed: The Risks of Using Popular Mental Health Apps with 14.7M Installs
KC&D entry on Clop's leak site
KC&D entry on Clop’s leak site (BleepingComputer)

Notably, Clop has targeted several high-profile organizations in the past, including universities, airlines, and tech companies. The U.S. Department of State has offered a substantial reward for information linking Clop’s activities to a foreign government.

As the investigation continues, Korean Air is urging employees to remain cautious and report any suspicious activity related to the breach. The airline is committed to safeguarding employee data and preventing further security incidents.

tines

Enhance Your IAM Strategy: Key Considerations

Discover why traditional IAM practices may fall short in today’s digital landscape and learn how to build a robust IAM strategy for your business.

Stay informed about the latest developments in the Korean Air data breach and follow recommended security measures to protect your personal information. As the investigation unfolds, Korean Air remains dedicated to ensuring the privacy and security of its employees.

Trending