Southwest Airlines Co.
ent_85376d9c95f34a8b9b72ce66
Disclosures
12
State AG · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
36,485
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Southwest Airlines Co.
- Normalized
- southwest airlines— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0000092380
- Domain
- None on record
Disclosure history (12)newest first
- Indiana State AGas victim2024-10-24
Southwest Airlines Co reported a data breach to the Indiana Attorney General. The breach occurred on 2024-08-16 and was reported on 2024-10-24. 1 Indiana residents were affected. 160 individuals affected in total.
- New Hampshire State AGas victim2023-06-26
Southwest Airlines Co. notified the NH AG of a third-party vendor (pilotcredentials.com) breach. Unauthorized access occurred ~April 30, 2023. Southwest learned May 3, 2023. 3 NH residents affected; data included names, SSNs, DOBs, driver's licenses. Southwest terminated vendor, moved to internal portal, notified law enforcement, offered credit monitoring.
- Massachusetts State AGas victim2023-06-23
Southwest Airlines Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-23. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-06-23
Southwest Airlines Co reported a data breach to the Indiana Attorney General. The breach occurred on 2023-04-30 and was reported on 2023-06-23. 41 Indiana residents were affected. 3,009 individuals affected in total.
- Maine State AGas victim2023-06-23
Southwest Airlines Co. reported a data breach due to an external system hack on April 30, 2023, which was discovered on May 3, 2023. The incident affected 3,009 individuals, exposing personal identifiers such as names and driver's license or non-driver identification card numbers. The company notified affected consumers on June 23, 2023, and offered two years of identity theft protection services through Equifax.
- Montana State AGas victim2023-06-23
Southwest Airlines Co. notified Montana residents of a data security incident involving third-party vendor pilotcredentials.com. An unauthorized actor accessed vendor systems around April 30, 2023, obtaining applicant data including names. Southwest discovered the incident on May 3, 2023, terminated the vendor relationship, engaged law enforcement, and offered two years of Equifax identity protection services.
- New Hampshire State AGas victim2018-06-08
Southwest Airlines Co. filed a supplemental notice with the New Hampshire AG regarding a data incident involving its former third-party vendor, Orbitz. Unauthorized access occurred between Oct 1, 2017 and Dec 22, 2017. Data accessed included names, payment card numbers, and contact info for hotel reservations made via Southwest.com. 244 NH residents were notified.
- Massachusetts State AGas victim2018-04-21
Southwest Airlines Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-21. 400 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-04-20
Orbitz LLC notified New Hampshire AG that an unauthorized third party accessed personal information (names, payment card numbers, addresses) on a legacy booking platform between Oct-Dec 2017. Incident discovered March 1, 2018. 243 NH residents affected. Southwest Airlines systems were not compromised. Orbitz engaged forensic investigators and law enforcement, and offered credit monitoring.
- Washington State AGas victim2018-04-20
Southwest Airlines Co. notified the Washington AG that Orbitz LLC, a third-party vendor, experienced unauthorized access to its legacy booking platform between Oct 1 and Dec 22, 2017. Access may have included names, payment card numbers, and addresses for 555 WA residents. Southwest's own systems were not affected. Orbitz engaged forensic investigators and law enforcement.
- California State AGas victim2018-04-20
Orbitz notified Southwest Airlines customers that an unauthorized third-party may have accessed personal information on a legacy Orbitz platform powering Southwest.com between October 1, 2017, and December 22, 2017. The incident was discovered on March 1, 2018. Affected data included names, payment card numbers, expiration dates, phone numbers, email addresses, and physical/billing addresses. Orbitz engaged forensic experts, enhanced security, and offered one year of credit monitoring.
- Oregon State AGas victim2018-04-20
Southwest Airlines co. reported a data breach to the Oregon Attorney General. The breach was reported on 2018-04-20. The breach occurred during 10/1/2017 - 12/22/2017. The breach was discovered on 3/22/2018. 36,485 individuals were affected. Notice was sent on 4/20/2018.
Supply-chain cascadesreviewed and confirmed
- Southwest Airlines Co.’s filing is one of at least 6 in the Orbitz Worldwide, LLC supply-chain incident (2018).