Data Protection Act 1998 conditioned the issue of a £500 000 fine – the biggest penalty stipulated by the Act – for Cathay Pacific following the data breach which occurred between 2014-2018.
As the incident happened before GDPR came into force the new European law will not affect the company.
Personal data of 9.4 million passengers was impacted between October 2014 and May 2018. Names, passport details, a number of credit cards, dates of birth, emails, addresses, phones and travel history information got exposed.
Cathay Pacific appeared to make a few security mistakes – backup files were unprotected, web-facing servers happened to be unpatched, OS lacked support and antivirus didn’t meet the requirements.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!