TrendingVideosIndia
Opinions | CommentEditorialsThe MiddleLetters to the EditorReflections
UPSC | Exam ScheduleExam Mentor
State | Himachal PradeshPunjabJammu & KashmirHaryanaChhattisgarhMadhya PradeshRajasthanUttarakhandUttar Pradesh
City | ChandigarhAmritsarJalandharLudhianaDelhiPatialaBathindaShaharnama
World | ChinaUnited StatesPakistan
Diaspora
Features | The Tribune ScienceTime CapsuleSpectrumIn-DepthTravelFood
Business | My MoneyAutoZone
News Columns | Straight DriveCanada CallingLondon LetterKashmir AngleJammu JournalInside the CapitalHimachal CallingHill View
Don't Miss
Advertisement

Data of 12 lakh SpiceJet passengers breached, says security researcher

Unlock Exclusive Insights with The Tribune Premium

Take your experience further with Premium access. Thought-provoking Opinions, Expert Analysis, In-depth Insights and other Member Only Benefits
Yearly Premium ₹999 ₹349/Year
Yearly Premium $49 $24.99/Year
Advertisement

New Delhi, January 31

Advertisement

A data breach has hit one of India’s largest privately-held carriers, SpiceJet, affecting 1.2 million passengers in the country.

Advertisement

Security researchers who first revealed the data breach told TechCrunch that they gained access to the carrier’s systems by brute-forcing the system’s easily guessable password.

In a statement, SpiceJet said: “At SpiceJet, safety and security of our fliers’ data is sacrosanct. Our systems are fully capable and always up to date to secure the fliers’ data which is a continuous process. We undertake every possible measure to safeguard and protect this data and ensure that the privacy is maintained at the highest and safest level”.

The private information of more than 1.2 million passengers were contained on an unencrypted database backup file of SpiceJet’s systems, according to the report.

Advertisement

Also read: Thousands of Instagram users’ personal details exposed

The details that the security researchers got access to as part of what they described as their “ethical hacking” efforts included the passenger’s name, their phone number, email address and their date of birth.

According to the security researchers, the database was easily accessible to everyone who knew where to look.

Despite alerting SpiceJet about the data base, the researchers said they did not receive a meaningful response from the carrier.

This led them to alert the Indian Computer Emergency Response Team (CERT-In).

The aviation major, however, did not confirm CERT-In’s findings. — IANS

Advertisement
Show comments
Advertisement