Delta Air Lines, Inc.
bd_01d416aae72ef6a0 · schema v1 · pii pii-v1
Full breach record for Delta Air Lines, Inc. →6 incidents on fileDelta Air Lines notified Hawaii customers of a third-party breach involving [24]7.ai, a chat service provider. Malware on [24]7.ai's systems between Sept 26 and Oct 12, 2017, allowed unauthorized access to payment card data (name, address, card number, CVV, expiration) for purchases made on delta.com. Delta engaged law enforcement and forensic teams, offered two years of free credit monitoring, and notified affected customers via mail on April 11, 2018.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Mar 28, 2018
Discovered
Apr 26, 2018
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.