Data breach at an external service provider for Luxair

fr en

Luxair S.A. would like to inform its customers that a security incident, resulting in a breach of personal data, has occurred at an external service provider working for Luxair.

<< Back
18/08/2023 |
  • Boeing 737-8  Luxair copy

This external service provider supports Luxair in communicating with its customers in the event of flight disruptions or delays, so that affected customers can receive meal vouchers and organize hotel reservations if necessary.

It turns out that the service provider in question hosts its data in a cloud, which was not adequately secured, contrary to the guarantees it had given in terms of information security, resulting in access via the Internet to the server on which Luxair customer data were processed.

As such, the booking data of customers whose flights had been disrupted between November 2020 and 4 July 2023, resulting in the granting of a meal voucher, a necessary hotel reservation because of such disruption, or any disruption warning communication by SMS, was made accessible to unauthorized third parties. This does not, however, mean, that all data has actually been accessed.

The server in question has now been re-secured, preventing the data from being accessed. For the time being, the provider's services, for vouchers and hotel bookings, have been suspended until further notice.

On the basis of the data made accessible in this way, passengers are advised, in order to protect themselves against any fraudulent use of their data, to be extra vigilant when receiving messages (particularly phishing) that could reproduce Luxair's visual identity or be based on data from past flights.

Here are some advices from Luxair to its customers, to avoid being victims of such acts of phishing:

  • It is important not to open e-mail attachments that look suspicious. First and foremost, it is necessary to make sure that the domain name of the e-mail corresponds to a legitimate e-mail address. The SPAMBEE initiative (link) enables to report and detect such e-mails;
  • Avoid sending confidential information via e-mail;
  • Finally, check that electronic devices (such as cell phones and computers) are up to date and report any suspicious incidents to BEE-SECURE, the Grand Duchy of Luxembourg's government initiative to promote the safe and responsible use of information technology (link).

Finally, a dedicated e-mail address (), enabling anyone wishing to obtain further information about this incident, to contact the Data Protection Officer, has been set up for.

Back to top  | << Back

Communiqués liés

1 Drees Sommer gewinnt Vision Zero Award (c) Vision Zero (002)
16/05/2024

Drees & Sommer lauréat du Vision Zero Award

Drees & Sommer, société leader dans le conseil et la réalisation de projets d...

Drees & Sommer
Delphine Berlemont PwC Luxembourg
15/05/2024 Personnalités

PwC Luxembourg welcomes New Head of Human Resources, Delphin...

PwC Luxembourg is delighted to welcome its new Head of Human Resources, Delphine...

pwc
BeSix
15/05/2024

BESIX RED relève les défis de 2023 grâce à l’unité e...

Malgré les défis sans précédent auquel le marché immobilier a fait face tou...

Besixred Luxembourg S.A
2015 06 09 Bourse-PG-1
15/05/2024

ION-owned LIST connects FastTrade electronic trading system ...

LIST, an ION company, today announces that it has successfully completed the cer...

Bourse de Luxembourg
Bâloise-Assurances-Luxembourg
15/05/2024 Personnalités

Nomination de Benoît Piccart en tant que Head of Corporate ...

Après plus de 30 années chez Baloise, Marc Folmer, Directeur de la Gouvernance...

baloise
assurance copy
14/05/2024

Votre monde, votre langue, votre assurance : l'Intelligence ...

AXA Luxembourg lance une initiative invitant les habitants et futurs habitants d...

AXA

Il n'y a aucun résultat pour votre recherche

We use cookies to ensure the best experience on our website. By accepting you agree the use of cookies. OK Learn more