Supply chain
⛓ Supply Chain
Malinda Air Third-Party Breach (September 2019)
Primary Source ↗Incident Details
Malinda Air locks down publicly exposed servers. Indonesian budget airline Malindo Air reported on September 19 it had locked down the formerly publicly exposed servers that had compromised passenger data. The airline had confirmed just one day prior that passenger data had been compromised and that it was working with Amazon Web Services and its e-commerce partner GoQuo to investigate the pr. “In light of the recent data leak from a third party vendor, Malindo Air’s cloud service provider, Amazon Web Services (AWS) Singapore has confirmed that all Malindo Air’s servers are fully secured with no further vulnerabilities. Confirmation has also been given to verify that no payment details have been compromised,” Malindo said in a statement. The South China Post reported that the data from millions of Malinda’s passengers were involved, but the company did not release any figures.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2019-09-01 Breach occurred
- 2019-09-19 Publicly disclosed