HackingStolen CredentialsEmployee Data InvolvedCREDENTIALSLowContained
Virgin America Inc.
bd_26e6b292829d75bc · schema v1 · pii pii-v1
Full breach record for Virgin America Inc. →Virgin America notified the California Attorney General that an outside party gained unauthorized access to its information systems containing employee and contractor login credentials. The incident was discovered on March 13, 2017. Virgin America engaged forensic experts, notified law enforcement, and required affected individuals to reset passwords.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100596
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2017
- Raw hash
- b525017e066cd89842c024577715fa4bb998b2a3667dd455a0d534d6db80745a
Reporting entity
- Name
- Alaska Air Group, Inc.norm: alaska air
Victim entity
- Name
- Virgin America Inc.norm: virgin america
Incident
- Discovered
- Mar 13, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.