Direct naar inhoud

Ad

app

Data of 22 EUR travellers leaked through bookings made via DGI Travel

Gepubliceerd op:

Sensitive data belonging to at least 22 EUR employees was leaked via DGI Travel at the beginning of August. The underlying Travelport platform used by DGI was found not to be properly secured. As a result, information from at least tens of thousands of trips from Travelport could be viewed by an unknown party. The data may have included telephone numbers and email addresses.

Diversity Travel krijgt veel klachten, zoals anuleringen en verkeerde boekingen.

Image by: Ami Rinn

According to a university spokesperson, DGI Travel reported that the leak involved 22 trips made by 22 different EUR staff in July and August. The university informed those people personally. All staff who use DGI received a message about the leak.

It is not known whether the data was also stored or distributed, but it is certain that an unknown party viewed data relating to at least tens of thousands of trips on 6 and 7 August. Travelport discovered the leak on 20 August; DGI informed the university of it on 3 September.

‘Investigation under way’

It therefore took around four weeks since the leak before the university could warn its staff. “We believe that we should be informed about a data breach as soon as possible, and we have also raised questions about this with DGI. Further investigation is still under way. Colleagues who travelled on 4 September or shortly afterwards were proactively informed about the leak, and DGI users were asked to be extra alert to suspicious emails or messages”, the spokesperson wrote.

The leak did not occur at DGI itself, but on a booking platform used by DGI. The platform belongs to the company Travelport. At Travelport, existing trip data could temporarily be viewed using only a reference number consisting of just six uppercase letters and numbers. This was a configuration error: this should only have been possible using a combination of the reference number and the booker’s surname.

Special requests in the data

Travelport and DGI have not disclosed exactly how many trips were leaked. It is likely that the figure is at least tens of thousands. A Turkish regulator states on its website that 73,958 people were affected, based on reference numbers created in Turkey. Figures for other countries, such as the Netherlands, have not been disclosed. Travelport and DGI did not answer EM’s questions about specific figures for the Netherlands.

Travelport does state on its website which data may have been viewed. This includes the names on bookings, reservation numbers, email addresses, telephone numbers, information about flights, hotels, car hire and train tickets, special requests for people with, for example, a disability or dietary requirements, and loyalty programme card numbers. According to the company, passport, identity card and credit card numbers were not leaked because they were not available on the ‘hacked’ service.

Een lijst met artikelen

De redactie

Comments

Leave a comment

If you post a comment, you agree to our house rules. Please read them before you post a comment.

Your email address will not be published. Required fields are marked (required)

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Ad

app