DisclosureLens
Social EngineeringTransportation & LogisticsTransportationPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedTargetedIdentity (basic)Government IDFinancial accountHealth (basic)PIIMediumContained

Cargolux Airlines International SA

bd_bf4c192bc29ee9c0 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 25, 2019

Filed

Dec 6, 2019

To disclose

6 weeks

Affected

5state residents only

Confidence

65%
Full breach record for Cargolux Airlines International SA2 incidents on file

Cargolux Airlines International notified Montana residents of a phishing attack on Oct 25, 2019, compromising employee mailbox credentials. Attackers accessed HR data including SSNs, IDs, financial, and medical info. Cargolux reset passwords, engaged forensic consultants, provided security training, and offered 12 months of credit monitoring via ID Experts.

Incident timeline

undetected · 8 days
discovery → filing · 6 weeks / 42 days

Oct 17, 2019

Begins

Oct 25, 2019

Discovered

Dec 6, 2019

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.