Skip to main content
Breach Signal

Breach report

Travel & Hospitality

Cathay Pacific

Cathay Pacific says 9.4M passenger records affected by data breach

Hong Kong's flagship carrier revealed in October 2018 that hackers had accessed personal data, including passport numbers, on about 9.4 million passengers, months after it first detected suspicious activity on its network.

Reported by TechCrunch

Records exposed

9.4M

About 9.4 million passengers

Scale vs. largest on file

When
2018
How they got in
Network intrusion exploiting unpatched, internet-facing systems
Sector
Travel & Hospitality

On October 24, 2018, Cathay Pacific disclosed that data belonging to about 9.4 million passengers had been accessed without authorization, making it one of the largest airline breaches on record. The Hong Kong-based carrier said it first detected suspicious activity on its network in March 2018 and confirmed in May that personal data had been accessed. The roughly seven-month gap between detection and public disclosure became the central controversy of the incident.

The exposed information varied by passenger but included names, nationalities, dates of birth, phone numbers, email and postal addresses, passport numbers, Hong Kong identity card numbers, frequent flyer membership numbers, customer service remarks and historical travel information. About 860,000 passport numbers and 245,000 Hong Kong ID card numbers were involved. Around 400 credit card numbers were also accessed, but the airline said they had expired or lacked security codes. Cathay said passwords were not compromised and that it had seen no evidence the data had been misused.

Investigations later showed that attackers had been inside Cathay's systems for years. The U.K. Information Commissioner's Office found that the airline's network was first compromised as early as 2014 and that failures included unencrypted database backups, an internet-facing server left exposed to a vulnerability that had been publicly known for more than a decade, operating systems no longer supported by their vendors and inadequate multifactor authentication for remote access.

The delay drew sharp criticism from Hong Kong lawmakers, who summoned executives to explain themselves, and from the city's privacy commissioner, who opened an investigation and later issued an enforcement notice requiring the airline to overhaul its data security. Cathay said it had waited to disclose until it could determine which passengers were affected and what data was involved. In March 2020 the ICO fined the airline £500,000, the maximum allowed under the U.K. data protection law in force before GDPR. Cathay's shares fell sharply on the day of the announcement, adding to pressure on an airline already struggling financially.

The Cathay Pacific breach highlighted how long intruders can persist inside poorly maintained networks and how slow disclosure compounds reputational damage. It arrived just months after GDPR introduced 72-hour notification requirements in Europe, and it became a case study in why airlines, which hold passport and travel records sought by both criminals and intelligence services, need basic hygiene such as patching, encryption of backups and strong remote access controls.

More from the wire

More in Travel & Hospitality.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.