Cathay Pacific faces probe over massive data breach

Cathay Pacific faces probe over massive data breach

Airline has faced criticism for the seven-month delay in revealing breach

Credit: Dreamstime

Hong Kong's privacy commissioner will launch a compliance investigation into Cathay Pacific Airways over a data breach involving 9.4 million passengers, saying the carrier may have violated privacy rules.

The airline has faced criticism for the seven-month delay in its October revelation of the breach in the data, which it said had been accessed without authorisation, following suspicious activity in its network in March.

"There are reasonable grounds to believe there may be a contravention of a requirement under the law," Hong Kong's Privacy Commissioner for Personal Data, Stephen Wong, said in a statement.

"The compliance investigation is going to examine in detail, amongst others, the security measures taken by Cathay Pacific to safeguard its customers' personal data and the airline's data retention policy and practice," he added.

It will also cover Cathay's fully owned subsidiary, Hong Kong Dragon Airlines Ltd, or Dragon Air, some of whose passengers were affected by the breach.

A Cathay Pacific spokeswoman said in an email to Reuters that the airline was studying the statement and would "continue to cooperate fully with the authorities."

The privacy watchdog said it had received 89 complaints related to the cyber leak.

In addition to 860,000 passport numbers and about 245,000 Hong Kong identity card numbers, the hackers accessed 403 expired credit card numbers and 27 credit card numbers with no card verification value (CVV), Cathay said.

It was not immediately clear who was behind the personal data breach or what the information might be used for, but Cathay said there was no evidence so far that any personal information had been misused.

Under Hong Kong law, the privacy commissioner can call witnesses, enter premises and hold public hearings in the investigation, which will check if Cathay violated any requirement of the Personal Data (Privacy) Ordinance.

The controversy has spurred calls from politicians and privacy advocates for Hong Kong to revamp its laws to make the reporting of such potential data breaches mandatory.

Cathay's share price initially plunged to its lowest since June 2009 after the scandal but has rebounded and recovered all its losses. The stocks were up 1.7 per cent on Tuesday afternoon.

The data breach comes amid an airline turnaround to cut costs and boost revenue, after back-to-back years of losses, so as to better compete with rivals from the Middle East, mainland China and budget airlines.

In August, Cathay Pacific posted a narrower half-year loss on a strong rise in airfares and cargo rates and flagged expectations for a better second half, despite economic headwinds from mounting U.S.-China trade tension.

(Reporting by Hong Kong newsroom and Donny Kwok; Editing by Clarence Fernandez)

Follow Us

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Cathay Pacific Airways



How MSPs can capitalise on integrating AI into existing services

How MSPs can capitalise on integrating AI into existing services

​Given the pace of change, scale of digitalisation and evolution of generative AI, partners must get ahead of the trends to capture the best use of innovative AI solutions to develop new service opportunities. For MSPs, integrating AI capabilities into existing service portfolios can unlock enhancements in key areas including managed hosting, cloud computing and data centre management. This exclusive Reseller News roundtable in association with rhipe, a Crayon company and VMware, focused on how partners can integrate generative AI solutions into existing service offerings and unlocking new revenue streams.

How MSPs can capitalise on integrating AI into existing services
Access4 holds inaugural A/NZ Annual Conference

Access4 holds inaugural A/NZ Annual Conference

​Access4 held its inaugural Annual Conference in Port Douglass, Queensland, for Australia and New Zealand from 9-11 October, hosting partners from across the region with presentations on Access4 product updates, its 2023 Partner of the Year awards and more.

Access4 holds inaugural A/NZ Annual Conference
Show Comments