Personal data of AirAsia Malaysia, Indonesia and Thailand passengers allegedly leaked due to ransomware

Personal data belonging to 5 million AirAsia passengers via AirAsia Malaysia, AirAsia Indonesia and AirAsia Thailand may have been leaked after the airline was hit by a purported ransomware attack. It was alleged that AirAsia was a victim of a Daixin Team ransomware attack and the attackers have shared two CSV files which contain personal details of passengers and employees.

Sample data from CSV files shared to DataBreaches.net. Source: DataBreaches.net

The Daixin ransomware group has been on US’ Joint CyberSecurity Alert published on 21st October 2022. From the sample data, the CSV file contains the passenger ID, full name (first, middle and last), booking ID, total cost of ticket. Meanwhile, the CSV for employee data contains a wide array of details including photos, secret questions, secret answers, birth city, birth state, birth country and nationality.

According to DataBreaches, the ransomware attack took place on 11th and 12th November 2022 and it was alleged that AirAsia has responded to Daixin Team through a chat. After sharing the sample data, they claimed that AirAsia didn’t try to negotiate the ransom amount and had no intention of paying. The ransom amount was not disclosed but Daixin Team said they have avoided locking up critical files related to flying equipment as part of their avoidance of encrypting or destroying anything that could be life-threatening.

A ransomware attack usually involves a malicious file that will encrypt all data on the server and the victim will have to pay the ransom to get their data back. According to Akamai, 71% of organisations in Asia Pacific have paid ransom fees between USD 100,000 to USD 1 million (RM458,330 – RM4.58 million), while 13% have paid between USD 1 million and USD 5 million (RM4.58 million – RM22.92 million). Ransomware attacks can severely disrupt airline operations. In May this year, hundreds of passengers were left stranded after Indian-based SpiceJet was hit by an attempted ransomware attack.

Daixin Team’s spokesperson told DataBreaches that the poor organisation of AirAsia Group had spared the company from further attacks. While they have encrypted a lot of resources and deleted backups, they didn’t proceed to cause more damage. It said, the group refused to pick through the garbage for a long time. As our pentester said, “Let the newcomers sort this trash, they have a lot of time.”

Besides leaking the passenger info on their dedicated leak site, the Daixin team said it plans to reveal more information about the network including the backdoors privately and freely on hacker forums.

We have reached out to AirAsia for further details on the matter.

Malaysia has been seeing a rise in personal data breaches with at least 3,699 reported incidents since 2017. Back in 2019, Malindo Air (now Batik Air) acknowledged a data breach which came from two former employees of its eCommerce service provider. Most recently, there was a data breach at Carousell involving 2.6 million users while personal data allegedly from the National Registration Department (JPN) and Election Commission including eKYC photos were sold online.

Despite the major breaches involving the personal data of Malaysian citizens, caretaker Home Affairs Minister Dato Seri Hamzah Zainuddin denies it came from JPN, while caretaker Defence Minister Datuk Seri Hishamuddin Hussien said the data breach does not jeopardise national security.

[ SOURCE 2 ]

Related reading

Recent Posts

Charge+ deploys 6 EV charging bays at SKS City Mall JBCC

If you're heading to the new SKS City Mall at Johor Bahru City Centre (JBCC)…

20 hours ago

Puspakom backs officer as motorcycle trader ordered to pay RM80K over TikTok Live defamation

Puspakom Sdn Bhd (Puspakom) has reaffirmed its commitment to integrity and professional conduct following a…

2 days ago

Huawei FusionSolar9.0 launches in Malaysia with AI-driven, grid-stabilising solar and energy storage solution

Huawei has launched its FusionSolar9.0 Smart PV & ESS solution in Malaysia, marking a shift…

2 days ago

Hyundai Ioniq 6 N and Ioniq 5 N estimated price in Malaysia starts from RM450k

Hyundai Motor Malaysia (HMY) has officially opened the order books for its upcoming high-performance EV…

3 days ago

WCE now supports TNG eWallet PayDirect at all toll plazas

West Coast Expressway (WCE) is now PayDirect enabled and it is said to be the…

3 days ago

JomCharge x DBKL offers 50% off EV charging in Kepong this weekend

For this coming Labour Day holiday weekend, JomCharge x DBKL are offering 50% discount for…

3 days ago

This website uses cookies.