{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m"},"incident":{"slug":"2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m","title":"American Airlines discloses breach after phishing compromised employee mailboxes","date":"2022-07","date_precision":"month","year":2022,"victim_org":"American Airlines","sector":"Transportation & Logistics","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1708,"threat_actor":null,"summary":"American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.","how_it_worked":"Attackers phished American Airlines employees and captured their mailbox credentials. The consequences ran in two directions. Inbound, the mailboxes held correspondence containing customer and employee identity documents, passport and driver's licence numbers among them, which is what made a small number of accounts a reportable data breach. Outbound, the attackers used the genuine airline accounts to send more phishing, because a message that actually originates from an American Airlines address passes authentication checks and carries the brand's credibility with recipients. The airline said it had no evidence of misuse but notified affected individuals and offered identity protection.","lessons":"MFA on corporate mail plus data-loss controls that keep identity documents out of mailboxes limit both the exposure and the reuse of the account for onward phishing.","confidence":"Confirmed","sources":[{"title":"American Airlines discloses data breach after employee email compromise","url":"https://www.bleepingcomputer.com/news/security/american-airlines-discloses-data-breach-after-employee-email-compromise/","publisher":"BleepingComputer"},{"title":"American Airlines Says Personal Data Exposed After Email Phishing Attack","url":"https://www.securityweek.com/american-airlines-says-personal-data-exposed-after-email-phishing-attack/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-american-airlines-discloses-breach-after-phishing-compromised-employee-m"}}