Japan's skyticket says 14.6 million customer records may have leaked
Adventure Inc., the Japanese company behind the airfare comparison and booking site skyticket, said on October 9 that up to about 14.64 million customer records may have leaked after attackers broke into its systems. About 4.13 million of those records include a login password, stored as a hash. The company disclosed three separate incidents at once: a server intrusion, a break-in to a back-office system that held refund bank details, and a bus booking page that anyone could open without logging in.
Three incidents in one announcement
The largest one began on October 2. Over three days, attackers misused part of skyticket's admin functions and used them to reach other servers and data stored in the cloud. Adventure found the intrusion on October 5. The records at risk hold names (including the spelling used in passports), dates of birth, email addresses, phone numbers, postcodes and home addresses, the names of people who paid by bank transfer, and the hashed passwords. Adventure says passport numbers were not taken and that it does not store card numbers or passport images.
The second intrusion went through a vulnerability in skyticket's business management system on September 20 and was spotted on September 28. It exposed about 17,780 records used for refunds, with names, phone numbers and full bank account details: bank, branch, account type, account number and account holder. The company counts these by person, duplicates included, and says the investigation is still running. It has confirmed one unauthorised login to a member's account linked to this incident.
The third problem was a design flaw rather than a hack. From August 3 to October 1, the confirmation page for bus bookings could be viewed without logging in. About 12,000 bookings were exposed, with names, ages, dates of birth, contact details, payment amounts, routes and pickup points, as well as the names, ages and genders of fellow passengers.
How the company responded
Adventure suspended payments with saved cards around 18:00 on October 7 and began emailing affected customers on October 8. It asks users to change their passwords and to check their booking history and card statements. Security Measures Lab, a Japanese security news site, reported that a user who tried to change their password after getting the notice saw a server error and could not finish. Adventure still describes the main leak as possible rather than confirmed.
What skyticket customers should do
- Change the password everywhere you used it. A hash slows attackers down but does not stop them from cracking short or common passwords offline. If the same password protects your email or another shop, change it there first.
- Turn on two-factor sign-in for your email and other important accounts. Our plain guide to two-factor codes explains which kinds actually help.
- Treat travel and refund messages with suspicion. If the data was taken, fraudsters have real names, phone numbers and in some cases booking details. A call or SMS about a "refund for your flight" that asks for card or bank details should be checked by opening the skyticket site yourself.
- Watch your bank account. Adventure itself tells customers to look out for unexpected deposits and to check card statements.
For the 17,780 people whose refund bank details were exposed, the account number on its own does not let anyone withdraw money, but it gives scammers a convincing detail for a call that claims to come from the bank or from skyticket.