13 ms·
EasyJet admits a cyber-attack has affected approximately nine million customers
- eddieoz 6y agoBut they didn't reveal any details about it. They just told it was a highly sophisticated cyberattack. Guess?
- huy-nguyen 6y agoOf course the attacks have to be “highly sophisticated” in order to beat the “world-class” system that “highly paid” EasyJet security experts have put in place to secure customer data, which EasyJet “cares deeply” about.
- matteuan 6y agoMy guess is that some higher-up employee clicked on a bonus.pdf.exe and that's it
- bjohnson225 6y ago"highly sophisticated cyberattack" is just PR speak for "cyberattack" - and successful cyberattacks are far more likely to be the result of negligence from company holding the data than the sophistication of the attackers.
- bigiain 6y ago<sound fx=typing> https://www.shodan.io/search?query=mongodb https://www.shodan.io/search?query=mongodb Oh look, EasyJet huh? I wonder what's in there?
- malux85 6y agoIf EasyJets systems are anything like their customer service, their in-flight food, their baggage handling or their scheduling, this is not surprising.
- nicolaslem 6y agoIs baggage handling specific to an airline? It looks like it's a service provided by the airport.
- speedgoose 6y agoIt depends on the airport and the airline.
- adev_ 6y ago> Is baggage handling specific to an airline? It looks like it's a service provided by the airport. Generally you are right yes, it is airport service under one of the operating company of the airport. However easyJet and other low cost airline have generally a very vertically integrated system where they try to operate almost everything themselves to reduce cost. Some airport have entire dedicated terminal for them, I would not surprise if they manage also their luggage system in these airports.
- matteuan 6y agoTheir handling of refunds and cancellations...
- swarnie_ 6y agoAnd yet still not the worst airline in Europe, Ryanair takes that shitty award for some truly appalling business practises.
- gpderetta 6y agoAt least Easyjet seats are not slabs of hard plastic. Bus seats are significantly more comfortable than Ryanair "seats".
- 6y ago
- 88840-8855 6y agoCould be catastrophic, as I have my ID details saved there for quick checkin.
- mindracer 6y agoMe too, could be a lot of passports being cancelled and reissued shortly
- 88840-8855 6y agoThe question is: who will pay that? It costs around 100 Euro to renew a passport here in Germany.
- close04 6y agoThe individual, as usual. Even if there's some legal recourse the inconvenience and expense will be larger than the payoff. And there's no legal framework to just be compensated by default in such cases.
- kieranmaine 6y agoFrom https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-story.aspx?cid=2&newsid=1391756 https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-... "Other than as referenced in the following paragraph, passport details and credit card details of these customers were not accessed" The following paragraph says 2208 credit cards details were stolen.
- dazc 6y agoCancelling and renewing a passport is not a trivial matter either.
- Nextgrid 6y agoWhy would reissuing passports help? The old passport is still valid and only the government is actually able to tell whether it's cancelled (as they have access to the passport DB), but for all other intents and purposes (identity verification for banks, etc) the other passport still appears perfectly valid.
- eswat 6y agoNotice of cyber security incident: https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-story.aspx?cid=2&newsid=1391756 https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-...
- thinkingemote 6y agoThe CEO says " it has become clear that owing to Covid-19 there is heightened concern about personal data being used for online scams" Am I missing something here? This doesn't make sense really.
- HyprMusic 6y agoI imagine this data could easily be used for a scam, considering the vast majority of these customers would have had flights cancelled and are probably pending refunds. A simple "Your refund is being processed, please enter the details of the card you paid with" would be very convincing for all those desperate for their money back.
- Traster 6y agoIt makes perfect sense, the company has completely screwed up in a way that's totally unrelated to Coronavirus, and now they're trying to conflate the two issues.
- rajnathani 6y agoThis statement is too funny. For those looking for the quote in the article, you will find it in the duplicate HN post's [0] article [1], of which its comments were merged into this thread. [0] https://news.ycombinator.com/item?id=23233619 https://news.ycombinator.com/item?id=23233619 [1] https://www.theguardian.com/business/2020/may/19/easyjet-cyber-attack-customers-details-credit-card https://www.theguardian.com/business/2020/may/19/easyjet-cyb...
- morsch 6y agoAny customer data, and especially PII, needs to be toxic. The toxicity needs to increase super-linearly with the total amount of data, because the value of leak does, too, while the difficulty of the breach probably does not. It needs to be so expensive to store extensive data of millions of people that companies (or for that matter, the government) cannot wait to get rid of it. Currently, most online shops nudge me towards opening an account and letting them store my data indefinitely (to facility marketing and reduce friction). They should do the opposite, nudge me towards not causing them the hassle of storing my data beyond the immediate business transaction.
- jimkleiber 6y agoI built an app back in 2012 for emotional journaling and I tried to collect as little data as possible from the user because I didn’t want to have the burden and legal responsibility to guard all that deep data. Many people in SV told me I was crazy not to collect data. It does make it harder to develop the app with so much uncertainty about how people are using it, yet I felt much more free knowing I wasn’t one hack away from exposing people’s lives.
- ta17711771 6y agoWhy not ask them?
- jimkleiber 6y agoI'm not sure to which part you're referring...ask them what?
- bigwavedave 6y agoI believe he's suggesting that since you don't collect any more data than necessary, you ask the users how they use your app instead.
- jimkleiber 6y ago
- chockablock 6y agoDupe of https://news.ycombinator.com/item?id=23233619 https://news.ycombinator.com/item?id=23233619
- martimarkov 6y agoHaving worked with EJ I just wanted to point out their system are insanely fragile. They never notified us about breaking changes and the system itself would go down multiple times. There was no CS when something goes wrong. And this was their B2B api. And from talking to ppl who were working in EJ a lot of things were being done on excel spreadsheets and emailed across. Just wanted to give this info as a sort of reference. I remember when I first found out how they worked that I was so shocked that it wasn’t more of public knowledge
- altacc 6y agoInteresting to hear, although a lot of companies still rely on emailing documents to each other. A few years ago I interviewed with a consultancy that provided a lot of development work for easyJet. They were operating under an old model of both work organisation and technology and not very keen to change. Interview went OK until I met the company CTO, who's personality left a lot to be desired. We ended up having a heated discussion about the need to innovate, or not in his case. Unsurprisingly, I never heard back from them.
- martimarkov 6y agoI think I even know the person you are talking about and yeah... :D I do feel that there is a culture in these big OLD (=old ibm mentality) where there is no need to innovate and it always costs a lot to do things right. The only reason they do is because some engineers are really pushing for it and making it happen.
- scoutt 6y agoBut they "take issues of security extremely seriously"... Typical. When are we going to get tired of the same PR, damage-controlling, bullshit that we all know are blatant lies? EDIT: we need a GDPR hero.
- kryogen1c 6y agostories like this make me so sad. its so clearly a result of the race-to-the-bottom system for journalism. theres a single word quoted from an unlisted source. how did we all get here? this is out of the BBC for christs sake. who's more foolish? the fool, or the fool who follows him?
- shakna 6y agoThe official incident notice is here [0]. > Following discussions with the Information Commissioner's Office ("ICO"), the Board of easyJet announces that it has been the target of an attack from a highly sophisticated source. [0] https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-story.aspx?cid=2&newsid=1391756 https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-...
- jacquesm 6y ago"Highly sophisticated" -> so we don't look like we're dumb.
- helsinkiandrew 6y agoWhat's your problem with it? The original story was broken by Reuters: https://uk.reuters.com/article/uk-easyjet-cyber/easyjet-hit-by-cyber-attack-hackers-access-nine-million-customers-details-idUKKBN22V1J3 https://uk.reuters.com/article/uk-easyjet-cyber/easyjet-hit-... Easyjet have reported the problem to the LSE: https://www.londonstockexchange.com/exchange/news/market-news/market-news-detail/EZJ/14545747.html https://www.londonstockexchange.com/exchange/news/market-new...
- GEBBL 6y agoReally tough on an already struggling airline. Wonder if their security team were fully in place recently?
- ollyculverhouse 6y agoEasyjet have been a main airline within the UK for many many years. They may be struggling because of the current environment but this isn't a small operation who wouldn't have a security team.
- cranekam 6y agoNot really "already" since the attack became known in January, before Covid-19 decimated the industry. Were you suggesting that they were already struggling? They made a profit of over £400M in 2019 so it doesn't sound like things were too bad. Of course, this news doesn't help them now, but it doesn't seem to me like "poor old EasyJet, down on their luck and now this".
- noad 6y agoWhat a stupid headline. Just a blatant falsehood in the title of the article. Why are journalists (still) so bad at this?
- davidhyde 6y agoI recon the more sensationalist they make the title and article the better. It doesn’t matter that it is technically inaccurate. It balances out the typically false response from these companies which usually starts with “We take the security of our customers data very seriously...”
- rzzzt 6y agoWould it help to see a more "honest" letter of apology from a company? What would that look like?
- agustif 6y agoClickbait titles is the new journo
- jbverschoor 6y agoTime for datapoint tax, which will reimburse victims of these crimes
- hammock 6y agoSomeone could hack themselves constantly and get paid to do it
- rorykoehler 6y agoAnd risk going to prison for a long time.
- hammock 6y agoPointing out unintended consequences. The rule suggested would tend to increase, however slightly, crimes commmitted.
- deleted 6y ago[deleted]
- nkrisc 6y agoYes, there are many criminal ways to make money. It would be nothing new. For example, burning your house or failing business down to make a claim is probably as old as insurance.
- mangatmodi 6y agoInteresting. Were they storing/operating unsalted plaintext credit card info? I hope not.
- fargo 6y agomost people do unfortunately
- InsomniacL 6y agoOnly a couple thousand had their Credit Card details stolen whereas nine million had information stolen. This sounds like they were able to access the database to steal customer information and plant code on the website to scrape any future transactions before the Credit Card information is encrypted in the database.
- Nextgrid 6y agoCredit card information is needed as-is to be able to make transactions so hashing (and thus salting) doesn’t apply. Encryption is the best you can do.
- afrcnc 6y agoOfficial statement: http://otp.investis.com/clients/uk/easyjet1/rns/regulatory-story.aspx?cid=2&newsid=1391756 http://otp.investis.com/clients/uk/easyjet1/rns/regulatory-s...
- pedrocr 6y agoEasyJet was the one hacked, the customers got their information stolen from the hack but were not themselves hacked.
- helldritch 6y agoThis reminds me of "identity theft". Someone didn't steal my identity, someone stole from the bank using my identity. It should really be called "bank fraud".
- dmurray 6y agoA great sketch about this https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- sshagent 6y agoWeird how i just assumed this would be Michell & Webb. I've not seen much of there stuff, but it just felt like it was going to be skit of theres
- gnufx 6y agoPerhaps we should let them know they're too predictable! (Ross Anderson rightly ranted on the topic somewhere.)
- gnufx 6y agoNew to me, but it was suggestive somehow of Mitchell and Web before watching it.
- gryzzly 6y agoUnless you are being sued by the bank as the one who stole the money and this happens in another country and the time to claim your innocence is out. Then it’s you who suffers the fraud, not the bank :/ (talking from personal experience of a close friend)
- abledon 6y agoGood, Cheap, or Easy. Pick Two.
- Raed667 6y agoWhat I don't see in this article, is how can I (as an EasyJet customer) check if my data was breached?
- mikro2nd 6y agohaveibeenpwned.com ?
- badRNG 6y agoWhile I strongly recommend HIBP, the EasyJet hack is not yet loaded into their site. https://haveibeenpwned.com/PwnedWebsites https://haveibeenpwned.com/PwnedWebsites
- johnspiral666 6y agoWish HIBP accepted PayPal, guess they're being ironic.
- ozim 6y agoThese affected customers will be contacted in the next few days. If you are not contacted then your information has not been accessed.
- brnt 6y agoThe number one reason I do not keep CC info, and why I don't fill out details wherever I can. I don't trust your security.
- nogabebop23 6y agogood luck buying a plane ticket from easyjet without giving them your CC info
- trickstra 6y agoSome banks can generate a virtual CC ad-hoc, so you could have different CC details per each transaction. It's rare, I wish my bank did it, but it exists.
- bitdivision 6y agoThere's often an option for whether to store CC info for future purchases. I assume that's what GP is referring to. I wouldn't be surprised if they stored it anyway though
- Aeolun 6y agoJust don’t buy from easyjet period. Nothing but bad experiences with them (sample size 1). Who the hell makes ‘boarding time’ the same as ‘airplane leaves gate’ time :S
- leejo 6y agoI just logged in to change my easyJet password: > Your password must be a single word between 6 and 20 characters in length and must not include the special characters # & + or space. Come on! This is ridiculous. If you're going to get hacked at least have a sane password policy.
- capableweb 6y agoStill better than my bank (one of Spain's biggest) that requires your password to be 8 (not less, not more) digits.
- gerdesj 6y agoUse "password" - eight letters and it's English and so should be safe on a Spanish site.
- capableweb 6y agoYou missed that we're only allowed to use digits/numbers. No letters!
- coremoff 6y ago72779673
- marsRoverDev 6y agoHSBC in France have the same, it's a huge motivator for me to switch away.
- jesterson 6y agoMay I know why? It's a problem if there is no 2FA but I doubt HSBC won't have 2FA and this password requirements.
- 6y ago
- gryzzly 6y agoSo I just went to easyjet.com and logged in and they don’t prompt to update my password. I wonder if failure to invalidate all accounts is their technical ignorance or if my account was simply not hacked? I assume the ignorance of course.
- KingOfCoders 6y agoSince January.
- snowwolf 6y ago> EasyJet said it first became aware of the attack in January. vs > The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible. So either EasyJet was delayed in their reporting of the breach, or the ICO didn't feel it was urgent to notify 9 million people that their data had been compromised. But it is now 4 months later?
- trickstra 6y agoTheir official statement says > we took immediate steps to respond to and manage the incident and engaged leading forensic experts to investigate the issue. We also notified the National Cyber Security Centre and the ICO. We have closed off this unauthorised access. Maybe the relevant supervising authority didn't find it important to notify those 9 million customers.
- snowwolf 6y ago> Maybe the relevant supervising authority didn't find it important to notify those 9 million customers. Which is a problem right? Now it emerges what has been breached. Including credit card data. Surely the prudent thing would have been to warn all their customers immediately to allow them to be on the lookout for malicious use of their data (phishing, etc.) and not wait until they have concluded their investigation.
- bigbizisverywyz 6y agoOh great, that probably explains the last few emails I got recently kindly telling me what my password is, and I should pay some bitcoin otherwise my weird browsing habits will be exposed to the world. (edit)Ah no, no mention of passwords being stolen, so I guess it's from somewhere else.
- Nextgrid 6y agoFrom my experience reporting various GDPR violations is it clear that the ICO does not actually want to enforce the regulation so this is not surprising.
- DangerousPie 6y ago> EasyJet said it first became aware of the attack in January. I thought GDPR required companies to disclose breaches within a few days. What happened there?!
- JadeNB 6y agoAlso on the front page: https://news.ycombinator.com/item?id=23233619 https://news.ycombinator.com/item?id=23233619 .
- AJRF 6y ago6 months ago I went through every single website in my safari keychain and changed their password, even if the password was already unique. I also removed my credit card at some point after this from every single website - and changed the card in real life. So even if there is a card number somewhere in a db, it's not valid anymore. I'm tech savvy and this still took around a day, and it was a pain in the ass but hopefully mitigates some of the fallout from this hack - but to be statistically safe while continuing to use online services, id have to wipe my passwords and cards every few months given the frequency of hacks. I couldn't expect my family to put this much effort into doing this frequently. The system of holding a central database is completely bust. It's just too juicy a target to keep the hackers at bay. I really wish there was more effort today spent on changing this centralised paradigm to a decentralised one - my personal data should live on my computer, and my computer only. It should never ever leave it. It should always be hashed. If there was some way for web apps to be distributed and ran on my own personal computer, with zero knowledge proofs verifying transaction on the third party services side we would seriously reduce the attractiveness of hackers going off these enormous databases. It needs to be as easy to secure this data as possible, and it needs to never be sucked up to somewhere else, and security patches need to be instantly applied over the top of my running kernel - without any hiccup. Impossibly difficult you will scoff. No one wants to run their own software. They absolutely would if the tech industry put any effort into it. Also the fines need increased massively to incentivise action in this direction. It should be business-ruining if you lose your customers data like this.
- gryzzly 6y agoIs it the case for anyone else that your login data is not invalidated? You’d think someone in their org would realize at least to invalidate the auth data? I managed to sign in without a problem :/
- beshrkayali 6y agoit still baffles me everytime why they wait for so long to admit it, and why there's no accountability for such incompetence.
- drra 6y agoI once worked with a high level executive that left EasyJet and praised the company on how lean and small the team was. Apparently too lean and too small.
- Aeolun 6y ago> EasyJet first became aware of the attack in January. It told the BBC that it was only able to notify customers whose credit card details were stolen in early April. Bull. Shit!
- dethos 6y agoBoth the BBC article and the incident notice (shared in other comments) contain very few details about the "highly sophisticated cyber-attack". When such details are omitted I tend to suspect that "highly sophisticated" is sugarcoating some kind of negligence or bad security practices.
- cjrp 6y agoDitto. What if "highly sophisticated" actually means "stumbled upon easyjet.com/backups/latest_db_dump_w_passwords-SENSITIVE.sql"
- FearNotDaniel 6y ago> Stolen credit card data included the three digital security code - known as the CVV number - on the back of the card itself. I always thought that PCI-DSS standards mandate that the CVV must never be stored; I get that card number and expiry date may be stored for customer convenience purposes, speeding checkout when returning for a second purchase, but how on earth could they be compliant if they are stashing away CVVs somewhere?