EasyJet has admitted that a “highly sophisticated cyber-attack” has affected approximately nine million customers.
It said email addresses and travel details had been stolen and that 2,208 customers had also had their credit card details “accessed”.
The firm has informed the UK’s Information Commissioner’s Office while it investigates the breach.
EasyJet first became aware of the attack in January.
It told the BBC that it was only able to notify customers whose credit card details were stolen in early April.
“This was a highly sophisticated attacker. It took time to understand the scope of the attack and to identify who had been impacted,” the airline told the BBC.
“We could only inform people once the investigation had progressed enough that we were able to identify whether any individuals have been affected, then who had been impacted and what information had been accessed.”
Stolen credit card data included the three digital security code – known as the CVV number – on the back of the card itself.
EasyJet added that it had gone public now in order to warn the nine million customers whose email addresses had been stolen to be wary of phishing attacks.
It said that it would notify everyone affected by 26 May.
It did not provide details about the nature of the attack or the motives, but said its investigation suggested hackers were targeting “company intellectual property” rather than information that could be used in identity theft.
“There is no evidence that any personal information of any nature has been misused, however, on the recommendation of the ICO, we are communicating with the approximately nine million customers whose travel details were accessed to advise them of protective steps to minimise any risk of potential phishing.
Source : Here