Several travel companies in Japan have reported potential data breaches, raising concerns that customers’ personal information might have been compromised amid a series of cyberattacks in the country. The affected companies include Adventure, which operates the travel booking website Skyticket, travel agency H.I.S. and travel technology company Temairazu. In the case of Skyticket, up to 14.64 million customer records may be at risk, approximately 4.13 million of which may include members’ login passwords, according to its operator.
The company said Friday that data stored on internal servers and in the cloud had been accessed without authorization between Oct. 2 and Oct. 4. Skyticket’s bus reservation service and business management system were also allegedly affected by unauthorized access between August and October. The potentially jeopardized information includes customers’ names, dates of birth, addresses, phone numbers and email addresses.
Passport numbers and credit card information were not leaked, according to the company. In response, the company said it had blocked the unauthorized access and was investigating the incidents. It also temporarily suspended payments using saved credit cards and warned customers of potential phishing attempts via email, text and phone calls.
The company apologized and pledged to strengthen its security measures to prevent future incidents. Major travel agency H.I.S., meanwhile, said Wednesday that the passport information of up to 627 people might have been leaked following unauthorized access at its Thailand-based subsidiary, H.I.S. H.I.S said the incident took place in December last year and that safety measures had been put in place but that an investigation later revealed passport information, including customers’ dates of birth and passport numbers, could have been compromised.
The company said the announcement was delayed because its manual investigation was complicated by large amounts of unrelated data being mixed in with personal information. Travel technology company Temairazu also reported unauthorized access to its systems. Sept 28, the company said a third party had accessed its travel booking service on Sept. 21, potentially leading to customers receiving fraudulent text messages seeking their banking details.
Temairazu said it had blocked the unauthorized access and restored its services.
Extract — continue reading at the source.