Delta Air Lines, Inc.
bd_3fd5fb2b29a0de18 · schema v1 · pii pii-v1
Full breach record for Delta Air Lines, Inc. →6 incidents on fileDelta Air Lines notified customers and regulators of a cyber incident involving third-party vendor [24]7.ai. Malware in the vendor's chat software on delta.com desktop captured payment card data (name, address, card number, CVV, expiration) for customers who made purchases between Sept 26 and Oct 12, 2017. Delta engaged law enforcement and forensics, and is offering 2 years of credit monitoring to up to 825,000 affected US customers.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Mar 28, 2018
Discovered
Apr 11, 2018
Filed
vs. sector median
10 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_286e451dc4b1279e2018-04-12 · +1dCandidate
- Oregon State AGbd_766cb69bdc29cf102018-04-13 · +2dVerified by operator
- California State AGbd_c8ee1d64322889022018-04-13 · +2dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.