Delta sues AI vendor for exposing customers’ data in 2017

Date:

Share post:

Delta Airlines sued an artificial intelligence company, which offers chatbot services on Delta’s website, for its lax security measures that caused a 2017 data breach. The airline has filed a lawsuit in the U.S. District Court in New York against the vendor, claiming its poor security and weak passwords led to the data breach that exposed around 825,000 Delta customers.

Delta Airlines stated that the vendor took around 6 months to disclose the data breach. The carrier also stated the vendor disclosed breach details via LinkedIn instead of contacting it directly. According to the lawsuit, the breach exposed customers’ names, contact numbers, email addresses, and credit card information.

The vendor allowed its employees to use the same login credentials and didn’t use multi-factor authentication, according to the lawsuit.

“What’s particularly interesting about this situation is that Delta seems to have had contract provisions and had its provider sign a GDPR compliance addendum in February 2018 requiring immediate breach notification, five months before notifying Delta about the breach,” said Gary Roboff, Senior Advisor at Shared Assessments. “Delta says its vendor was aware of the breach when it signed that agreement.”

“If Delta actually used the words ‘adequate security’ instead of defining more precisely what good security hygiene means, that could be a problem,” Roboff added.

Recently, the U.K. Information Commissioner’s Office (ICO) fined British Airways with £183.39 million ($230 million) after the airline failed to protect its customers’ data. The proposed fine relates to a data breach notified to the ICO by British Airways in September 2018, that exposed around 500,000 customers’ personal information.

The ICO said its investigation found that the breach compromised customer details, including login, payment card, name, address, and travel booking information, which is collected after being diverted to a fraudulent website. The data breach, which began in June 2018, occurred due to the poor security measures to protect customer information, ICO stated.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...