Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Delta Cyberattack Exposes Customer Credit Card Details
News & Analysis

Delta Cyberattack Exposes Customer Credit Card Details

ISBuzz TeamBy ISBuzz TeamApril 6, 20188 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Is There Life Beyond the Credit Card?
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It has been revealed that the cyberattack the American airline Delta suffered last year may have exposed customer payment information. The airline said the incident involved (24)7.ai, a chat-services provider used by Delta and other companies. Delta says only “a small subset” of customers were affected, with payment information exposed from Sept. 26 to Oct. Security experts commented below.

Martin Jartelius, CSO at Outpost24:

How should Delta handle to breach?

As this relates to a PCI certified environment, the task of foresic investigations is with the card brands. The important part now is to handle the customer relations with transparency, and also to review the trusts between their own organization and their service providers.

As there is a known period the breach occurred, it is of course of importance to find out how it was possible for it to occur and how to prevent it from recurring.

What should customers do?

The breach occurred last year and remain undetected until a week ago. Customers should always be attentive to their card transactions. Depending on the maturity of security delivered by issuing banks, it is for example possible to block cards for card-not-present transactions without further authorization from the cardholder – however this does not hold true for all banks of geographical regions. As a customer, demand to be either be protected from damage, or provided adequate technical protection by your card issuer.

Do you have any comments around the payment platform that exposed the details?

Delta, as any other organization hosting web content, must consider that any instance when logic flows from one application to another, there is a transfer of trust – trust you have with your clients which is based on your brand and your relationship with your customers. This breach had its primary incident not with Delta, but with their partner – Yet it is stated as an issue affecting Delta. This is the reason understanding your entire digital eco-system ranging from outsourced processes to “cross domain” included scripts, including ad-networks, allows someone else to interact with your customers based on the trust those invest in you. And that also means, a good part of the negative impact of a breach with a partner will reflect back on that trust.

One should also note that this is a certified organization which have been through reviews and testing – Security is a continuous process, and compliance is not a guarantee of security. As long as banks hold their clients damage free, we can accept the current level of security. If consumers are to shoulder the costs or responsibility, much is still to be done regarding rather basic security in the payment card industry.

Craig Young, Computer Security Researcher at Tripwire:

“There are some interesting questions to ask in response to this disclosure. Why was the breach window so short? Were the attackers discovered and booted back in October? If so, why is it that we are only learning of the breach nearly six months later? If not, how can (24)7.ai be so confident of the scope of the breach? Were payment card providers notified sooner? Time is a critical factor for preventing fraud whenever there is a breach of financial data. Delta has assured customers that they won’t be held responsible for fraudulent charges but it seems likely that if fraudulent charges related to this have not already been identified, there is little hope that they will ever be connected to this breach.”

Lee Munson, Security Researcher at Comparitech.com:

“The cyberattack experienced by Delta highlights the many different facets of a data breach, from the good to the bad, as well as the unknown.

Obviously the big negative here is the fact that customers have potentially had their payment card data swiped, though the unknown factor is whether or not that information was encrypted, or how.

From an incident response point of view, it is a shame to learn to the attack has only now come to light, having occurred and been spotted last year, though we are, of course, unaware of when affected customers were notified.

On a more positive note, no personal information was stolen and Delta was quick to examine the breach and learn lessons from it.

We can only hope that affected customers have been offered appropriate support and advice and are now changing passwords where appropriate and examining credit reports with a keen eye.”

Satya Gupta, Co-Founder and Chief Technology Officer at Virsec:

“Once again, another breach raises troubling questions about why current security defenses are failing, and why organizations are dragging their feet with public breach notification. The company says it was notified in mid-March, yet the breach occurred six months earlier and was “quickly resolved.” Whether it’s a company or sub-contractor, the first impulse when a breach is discovered seems to be stalling and hoping it will not go public.

More broadly, we continue to rely on an outdated security model – protecting a porous perimeter, while hackers are often already inside, waiting to exploit vulnerabilities that may dwell for months. The focus has to shift to directly protecting applications and critical data – not relying on perimeter protection which is rapidly disappearing.”

Nick Bilogorskiy, Cybersecurity Strategist at Juniper Networks:

“Delta Air was not directly breached, it was affected by a third-party vendor breach. We saw this vector in play earlier this week with the Energy Transfer Partners third-party EDI breach.

It is no longer enough for large companies to only protect their own networks and internal systems from malware. Nowadays, business is conducted with the help of third-party service companies that provide savings by solving a piece of the puzzle for big companies, like online transaction support, for instance. In such cases, the third-party vendor increases the attack surface and the risk of a cybersecurity breach for the enterprise.

Third parties have been the vector of attack in many high-profile breaches and I anticipate this trend will continue. In recent years, 63 percent of breaches were traced to third-party vendors, according to the Soha System’s survey on third-party risk management. If a hacker can breach a company and pretend to be a legitimate vendor, they may have full access to a company’s network for months; plenty of time to monetize their attack.

A vendor often serves multiple customers, which can create complications and delays in incident response. It is crucial for companies to audit the security posture of their vendor just as rigorously as they do their own.

[24]7.ai operates global centers that outsource voice and chat agent services for sales and support, providing a channel of communication between their clients and customers. When such a channel is compromised, it can be quite damaging as the attackers can pose as support or sales managers and ask customers to provide sensitive information.”

Anthony James, Chief Marketing Officer at CipherCloud (San Jose, CA):

“It is an all too frequent headline – another high profile company breached with hundreds of thousands of customers’ personal information or credit card data stolen.  As with the Sears breach announced today, the 3rd party companies are the weakest link in the security chain.  The unfortunate realization that the largest brands are being impacted by their smaller partner companies should inform any organization when they establish their security practices and controls.

The question needs to be asked, who are our partners, what are their security practices, what data are we sharing, and what systems will they have access to?  In this example, [24]7.ai – the software service provider for Sears (and many other large retail and airline brands) – became the source for the breach exposing customer credit card data.

With data being the core asset cyber thieves are targeting, new approaches to data protection need to be implemented. There are plenty of new technology approaches to secure data when it is at rest, in flight and in use. These strategies need to be implemented when companies have access to critical customer data.” 

Mounir Hahad, Head of Juniper Threat Labs at Juniper Networks:

“The fact that these two breaches have been discovered in September and March, respectively, means there may be a systemic issue that has been present for at least the past six months within the area of compromise.

It is important to understand that this breach is different from some past breaches, such as Target, where the third-party vendor was a vehicle for an intrusion into the final victim’s own network. In the case of SaaS offerings, a threat actor may not even need to breach your network, siphoning off your data directly from the third-party vendor that you do business with instead. In other words, it is just as important to assess the security posture of a vendor you allow into your network as a vendor you exchange information with to provide you with a service. At the end of the day, it’s companies like Delta Air and Sears that end up in the news, not so much the third-party vendor.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}