Delta Air Lines, Inc.
ent_07d796cff8aa237aefa5f595
Disclosures
10
State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
825,000
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Delta Air Lines, Inc.
- Normalized
- delta air lines— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- Q2CCMS6R0AS67HJMBN42
- SEC EDGAR CIK
- 0000027904
- Domain
- ir.delta.com
Disclosure history (10)newest first
- New Hampshire State AGas victim2018-07-18
Delta Global Services inadvertently emailed a spreadsheet containing personal information of approximately 700 employees to a small group of 45 current or former employees who did not normally have access. The data included names, addresses, phone numbers, emails, dates of birth, Social Security numbers, and employment application details. The incident occurred on June 18, 2018, and was discovered the same day. Recipients were instructed to delete the file. Approximately 2 New Hampshire residents were affected. The company offered 12 months of identity theft protection and provided additional security training.
- Hawaii State AGas victim2018-04-26
Delta Air Lines notified Hawaii customers of a third-party breach involving [24]7.ai, a chat service provider. Malware on [24]7.ai's systems between Sept 26 and Oct 12, 2017, allowed unauthorized access to payment card data (name, address, card number, CVV, expiration) for purchases made on delta.com. Delta engaged law enforcement and forensic teams, offered two years of free credit monitoring, and notified affected customers via mail on April 11, 2018.
- South Carolina State AGas victim2018-04-18
Delta Air Lines notified customers of a data breach involving third-party vendor (24]7.ai. Malware on (24]7.ai's software allowed unauthorized access to payment card data (name, address, card number, CVV, expiration) for purchases on delta.com between Sept 26 and Oct 12, 2017. Delta was notified on March 28, 2018. No specific count of affected individuals was disclosed. Delta engaged law enforcement and offered 2 years of credit monitoring.
- Oregon State AGas victim2018-04-13
Delta Air Lines, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2018-04-13. The breach occurred during 9/26/2017 - 10/12/2017. The breach was discovered on 3/28/2018. 825,000 individuals were affected. Notice was sent on 4/11/20184/12/2018.
- Massachusetts State AGas victim2018-04-13
Delta Air Lines, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-13. 20,392 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2018-04-13
Delta Air Lines, Inc. reported a data security breach to the California Attorney General. The incident occurred between September 26, 2017, and October 12, 2017. Approximately 74,541 California residents were potentially impacted. The specific nature of the breach and data types are not detailed in the provided summary fields, but PII is assumed affected. No discovery date or specific attack vector is disclosed in the available metadata.
- Montana State AGas victim2018-04-12
Delta Air Lines notified customers of a data breach involving third-party vendor [24]7.ai. Malware in [24]7.ai's chat software accessed payment card data (name, address, card number, CVV, expiration) for purchases on delta.com between Sept 26 and Oct 12, 2017. Delta was notified on March 28, 2018. No definitive count of affected individuals was provided; Delta offered 2 years of credit monitoring.
- Delaware State AGas victim2018-04-11
Delta Airlines notified customers that a third-party chat service provider, [24]7.ai, experienced a cyber incident between Sept 26 and Oct 12, 2017. Malware in [24]7.ai's software allowed unauthorized access to payment card data (name, address, card number, CVV, expiration) for customers who purchased on delta.com during that window. Delta engaged law enforcement and forensic teams, offered 2 years of credit monitoring, and stated the incident was contained.
- New Hampshire State AGas victim2018-04-11
Delta Air Lines notified customers and regulators of a cyber incident involving third-party vendor [24]7.ai. Malware in the vendor's chat software on delta.com desktop captured payment card data (name, address, card number, CVV, expiration) for customers who made purchases between Sept 26 and Oct 12, 2017. Delta engaged law enforcement and forensics, and is offering 2 years of credit monitoring to up to 825,000 affected US customers.
- Massachusetts State AGas victim2012-11-29
Delta Air Lines, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-11-29. 1 Massachusetts residents were affected. The report records the breach type as both.
Supply-chain cascadesreviewed and confirmed
- Delta Air Lines, Inc.’s filing is one of at least 4 in the [24]7.ai supply-chain incident (2018).