Supply chain β›“ Supply Chain

KLM Third-Party Breach (January 2023)

πŸ“… 2023-01-01 🏒 Flying Blue
Primary Source β†—

Incident Details

Air France and KLM notify customers of account hacks. Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their accounts were breached. Flying Blue is a loyalty program allowing clients of multiple airlines, including Air France, KLM, Transavia, Aircalin, Kenya Airways, and TAROM, to exchange loyalty points for various rewards. “Our security operations teams have detected suspicious behavior by an unauthorized entity in relation to your account. We have immediately implemented corrective action to prevent further exposure of your data,” notifications sent to affected customers said. Third-party company: Flying Blue.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Flying Blue
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-01-01 Breach occurred
  2. 2023-01-06 Publicly disclosed