Supply chain
β Supply Chain
Southwest Airlines Third-Party Breach (June 2023)
Primary Source βIncident Details
American Airlines, Southwest Airlines disclose data breaches affecting pilots. American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data breaches on Friday caused by the hack of Pilot Credentials, a third-party vendor that manages multiple airlines’ pilot applications and recruitment portals. Both airlines were informed of the Pilot Credentials incident on May 3, which was limited solely to the systems of the third-party vendor, with no compromise or impact on the airlines’ own networks or systems. An unauthorized individual gained access to Pilot Credentials’ systems on April 30 and stole documents containing information provided by certain applicants in the pilot and cadet hiring process. Third-party company: Pilot Credentials.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Pilot Credentials
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-06-01 Breach occurred
- 2023-06-24 Publicly disclosed