Delta Air Lines, Inc.
bd_2ead6ef7cc038459 · schema v1 · pii pii-v1
Full breach record for Delta Air Lines, Inc. →6 incidents on fileDelta Airlines notified customers that a third-party chat service provider, [24]7.ai, experienced a cyber incident between Sept 26 and Oct 12, 2017. Malware in [24]7.ai's software allowed unauthorized access to payment card data (name, address, card number, CVV, expiration) for customers who purchased on delta.com during that window. Delta engaged law enforcement and forensic teams, offered 2 years of credit monitoring, and stated the incident was contained.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Mar 28, 2018
Discovered
Apr 11, 2018
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.