What happened
American Airlines disclosed in September 2022 that a phishing campaign had compromised a limited number of employee email accounts in July 2022, exposing personal information of customers and employees held in those mailboxes. Data types included names, dates of birth, postal addresses, phone numbers, email addresses, driver's licence numbers, passport numbers and some medical information. Breach filings reported 1,708 individuals notified. The compromised accounts were also abused to send further phishing.
How the deception worked
Attackers phished American Airlines employees and captured their mailbox credentials. The consequences ran in two directions. Inbound, the mailboxes held correspondence containing customer and employee identity documents, passport and driver's licence numbers among them, which is what made a small number of accounts a reportable data breach. Outbound, the attackers used the genuine airline accounts to send more phishing, because a message that actually originates from an American Airlines address passes authentication checks and carries the brand's credibility with recipients. The airline said it had no evidence of misuse but notified affected individuals and offered identity protection.
The control that would have caught it· our reading, not a claim from the sources
MFA on corporate mail plus data-loss controls that keep identity documents out of mailboxes limit both the exposure and the reuse of the account for onward phishing.
Sources (2)
- American Airlines discloses data breach after employee email compromiseBleepingComputer·bleepingcomputer.comOpen ↗
- American Airlines Says Personal Data Exposed After Email Phishing AttackSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.