ALASKA AIRLINES, INC.
bd_0bfcc8300dd56051 · schema v1 · pii pii-v1
Full breach record for ALASKA AIRLINES, INC. →Alaska Airlines notified the New Hampshire Attorney General of a data breach involving its third-party provider, Orbitz. Unauthorized access to a legacy Orbitz platform occurred between October 1, 2017, and December 22, 2017. The breach potentially exposed personal data (names, DOB, phone, email, address, gender) and credit card information for reservations made between Jan 1, 2016, and Dec 5, 2016. Approximately 4 New Hampshire residents were affected. Access was halted by Dec 22, 2017. Affected individuals were offered identity theft repair and 12 months of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_f8f8fec272114dc3Washington State AGfiled 2018-05-03Candidate
- bd_71acbbe5f78078adOregon State AGfiled 2018-05-04(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/alaska-airlines-20180503.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2018
- Raw hash
- 51e61ed8a595917295cd603c7de3befc447aaef486bf23e60eed5fd7914c25de
Reporting entity
- Name
- ALASKA AIRLINES, INC.norm: alaska airlines
Victim entity
- Name
- ALASKA AIRLINES, INC.norm: alaska airlines
Incident
- Discovered
- Mar 19, 2018
- Materiality determined
- —
- Notification sent
- May 4, 2018
- Affected individuals
- 4
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Filed notice with New Hampshire Attorney General
- Third party
- via Orbitz
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.