Supply chain β›“ Supply Chain

Southwest Airlines Third-Party Breach (June 2023)

πŸ“… 2023-06-01 🏒 Pilot Credentials
Primary Source β†—

Incident Details

American Airlines, Southwest Airlines disclose data breaches affecting pilots. American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data breaches on Friday caused by the hack of Pilot Credentials, a third-party vendor that manages multiple airlines’ pilot applications and recruitment portals. Both airlines were informed of the Pilot Credentials incident on May 3, which was limited solely to the systems of the third-party vendor, with no compromise or impact on the airlines’ own networks or systems. An unauthorized individual gained access to Pilot Credentials’ systems on April 30 and stole documents containing information provided by certain applicants in the pilot and cadet hiring process. Third-party company: Pilot Credentials.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Pilot Credentials
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-06-01 Breach occurred
  2. 2023-06-24 Publicly disclosed