Supply chain
⛓ Supply Chain
China Railway Third-Party Breach (February 2019)
Primary Source ↗Incident Details
Hacking, gone off the rails: Holiday travelers react to data breach · TechNode. We went to Beijing’s busiest train stations to ask travelers about the recent ticket-platform hacking incident. Train passengers may be riding into the Chinese New Year with concerns about data loss after thieves listed millions of train passengers’ information for sale on the black market. China’s official rail authority, China Railway, blamed a recent hacking on third-party ticketing vendors, often thought to be more convenient, though perhaps less secure, than the official railway ticketing platform, 12306.cn. Earlier this week, it was reported that China Railway moved to limit third-party apps’ access to train tickets.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2019-02-01 Breach occurred
- 2019-02-01 Publicly disclosed