CommuteAir •
ent_798f0d3c1501fc5dfcba5102
Disclosures
10
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
2,856
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CommuteAir •
- Normalized
- commuteair— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- commuteair.com
Disclosure history (10)newest first
- Massachusetts State AGas victim2023-01-26
CommuteAir, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-01-26. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-01-24
CommuteAir, LLC reported an external system breach (hacking) occurring on January 15, 2023, discovered on January 17, 2023. The incident affected 1,473 individuals, including 3 Maine residents. Affected data included names and personal identifiers. The company provided electronic notification and offered 12 months of Life Lock identity theft protection services.
- New Hampshire State AGas victim2023-01-24
CommuteAir, LLC notified the New Hampshire Attorney General on January 24, 2023, of a cybersecurity incident discovered on January 17, 2023. A security researcher identified an unsecured development server containing employee PII, including names, DOBs, addresses, and partial SSNs. Four New Hampshire residents were affected. CommuteAir took the server offline, reset credentials, engaged Mandiant for forensic analysis, and reported the incident to CISA.
- Montana State AGas victim2023-01-23
CommuteAir, LLC notified individuals of a data security incident discovered on January 17, 2023, following a security researcher's report of potential data exposure on a company server. The exposed data included a 2019 sample of the federal no-fly list, flight information, and employee PII (name, DOB, phone, address, last 4 SSN). CommuteAir took the server offline, engaged Mandiant for forensic investigation, and reported the incident to CISA.
- Indiana State AGas victim2023-01-18
CommuteAir, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2023-01-15 and was reported on 2023-01-18. 2 Indiana residents were affected. 1,473 individuals affected in total.
- New Hampshire State AGas victim2022-11-18
CommuteAir, LLC. reported that on November 9, 2022, an unauthorized individual gained access to a third-party HRIS via an API. The incident involved employee names, dates of birth, and the last four digits of SSNs. CommuteAir engaged cybersecurity consultants, notified law enforcement, and offered one year of identity theft protection.
- Indiana State AGas victim2022-11-17
CommuteAir, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2022-11-08 and was reported on 2022-11-17. 7 Indiana residents were affected. 2,856 individuals affected in total.
- Maine State AGas victim2022-11-17
CommuteAir, LLC, a commercial airline, reported an external system breach (hacking) that occurred on November 8, 2022, and was discovered the following day. The breach compromised the names and Social Security numbers of 2,856 individuals, including 6 residents of Maine. In response, the company provided electronic notification to the affected individuals on November 17, 2022, and offered 12 months of identity theft protection services through LifeLock.
- Montana State AGas reporting2022-11-17
Samaritan's Purse notified Montana residents of a data breach affecting its travel vendor. Unauthorized access occurred on August 24, 2022, confirmed on September 2, 2022. Traveler PII was accessed. No evidence of data download. Vendor isolated access and enhanced controls. Samaritan's Purse provided 2 years of LifeLock protection.
- Massachusetts State AGas victim2022-11-17
CommuteAir, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-11-17. 13 Massachusetts residents were affected. The report records the breach type as electronic.