Supply chain
β Supply Chain
KLM Third-Party Breach (January 2023)
Primary Source βIncident Details
Air France and KLM notify customers of account hacks. Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their accounts were breached. Flying Blue is a loyalty program allowing clients of multiple airlines, including Air France, KLM, Transavia, Aircalin, Kenya Airways, and TAROM, to exchange loyalty points for various rewards. “Our security operations teams have detected suspicious behavior by an unauthorized entity in relation to your account. We have immediately implemented corrective action to prevent further exposure of your data,” notifications sent to affected customers said. Third-party company: Flying Blue.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Flying Blue
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-01-01 Breach occurred
- 2023-01-06 Publicly disclosed