Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

American Airlines discloses breach after phishing compromised employee mailboxes

American Airlines · Transportation & Logistics · United States · July 2022

People or records affected
1,708
1.7K as reported

What happened

American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.

How the deception worked

Attackers phished American Airlines employees and captured their mailbox credentials. The consequences ran in two directions. Inbound, the mailboxes held correspondence containing customer and employee identity documents, passport and driver's licence numbers among them, which is what made a small number of accounts a reportable data breach. Outbound, the attackers used the genuine airline accounts to send more phishing, because a message that actually originates from an American Airlines address passes authentication checks and carries the brand's credibility with recipients. The airline said it had no evidence of misuse but notified affected individuals and offered identity protection.

The control that would have caught it· our reading, not a claim from the sources

MFA on corporate mail plus data-loss controls that keep identity documents out of mailboxes limit both the exposure and the reuse of the account for onward phishing.

Sources (2)

  1. American Airlines discloses data breach after employee email compromise
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. American Airlines Says Personal Data Exposed After Email Phishing Attack
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.