Delta Air Lines, Inc.
bd_ad9ecbbe227deabe · schema v1 · pii pii-v1
Full breach record for Delta Air Lines, Inc. →6 incidents on fileDelta Air Lines notified customers of a data breach involving third-party vendor (24]7.ai. Malware on (24]7.ai's software allowed unauthorized access to payment card data (name, address, card number, CVV, expiration) for purchases on delta.com between Sept 26 and Oct 12, 2017. Delta was notified on March 28, 2018. No specific count of affected individuals was disclosed. Delta engaged law enforcement and offered 2 years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Mar 28, 2018
Discovered
Apr 18, 2018
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.