Travel firms ‘failed to learn lessons’ from cyberattacks, Which? report claims

11 September 2020, 00:04

Passengers at Heathrow Airport’s Terminal 5
Coronavirus – Mon Jul 27, 2020. Picture: PA

An investigation by the consumer group claims firms such as Marriott, British Airways and easyJet have hundreds of flaws in their sites.

Travel firms have failed to secure their websites from hackers despite previous cyberattacks, consumer group Which? has claimed in a new report.

It says its own investigation found vulnerabilities in websites linked to Marriott, British Airways and easyJet, each of which has previously been the subject of high-profile data breaches.

This research found hundreds of flaws on sites linked to the three companies, Which? says, as well as on some domains linked to American Airlines and Lastminute.com.

The consumer group said it had looked at the security of websites operated by 98 travel companies – including airlines, tour operators, hotel chains and booking sites – examining cybersecurity on not just their main websites, but also related sites, including promotional sites, spin-off business and employee log-in portals.

According to the research, almost 500 issues were found on sites linked to Marriott, with more than 100 judged to be high-risk or critical by Which?

Marriott was hit by a major data breach in 2018, when it admitted the guest records of 339 million customers had been accessed, an incident for which it was fined £99 million by the Information Commissioner’s Office (ICO).

Travel companies must up their game and better protect their customers from cyber threats, otherwise the ICO must be prepared to step in with punitive action, including heavy fines that are actually enforced

Rory Boland, editor of Which? Travel

In May this year, the company said the details of as many as 5.2 million customers may also have been accessed in a second breach.

Elsewhere, 115 vulnerabilities were found on websites linked to British Airways, including 12 which were identified as critical.

BA was issued with a record £183 million fine last year by the ICO after hackers gained access to the personal data, including payment information, of about half a million customers.

The investigation said it also found issues on sites linked to easyJet, which confirmed its own data breach earlier this year, affecting nine million customers, more than 2,000 of whom had credit card details exposed.

Which? said it identified 222 vulnerabilities on easyJet sites, including two critical flaws.

Rory Boland, editor of Which? Travel, said Marriott, British Airways and easyJet had “failed to learn lessons from previous data breaches” and were leaving customers exposed to cybercriminals.

All companies have to be vigilant to defend against criminal cyber activity and we will continue to constantly review and strengthen our systems

easyJet

“Travel companies must up their game and better protect their customers from cyber threats, otherwise the ICO must be prepared to step in with punitive action, including heavy fines that are actually enforced,” he said.

“The Government must also allow for an opt-out collective redress regime that deals with mass data breaches – so that companies that play fast and loose with people’s data can be held to account.”

Responding to the investigation, easyJet said it had taken action on nine web domains flagged to it.

“EasyJet always takes the security of our systems and the protection of our customer and employees’ data very seriously, complying with relevant legislation,” the company said.

“Like many companies, easyJet has a number of subdomains which provide a range of functions, including test sites not in use by customers, resources for staff, and sites to provide additional services and information for customers such as our digital inflight magazine or our bistro menu.

“As soon as potential vulnerabilities on nine subdomains were brought to our attention, we investigated this in addition to our regular security reviewing processes, and of those, three have been removed as were expired sites, potential vulnerabilities on one active site have been resolved, and we will be resolving the potential vulnerabilities for the remaining five subdomains in the coming days.

We have multiple layers of protection in place and are satisfied that we have the right controls to mitigate vulnerabilities identified

British Airways

“These subdomains are in no way linked to our core website and we have seen no evidence of any malicious activity on these sites, and none store any customer passwords, credit card details or passport information.

“We had already started a full review of all domains using a risk-based approach.

“This would have identified and resolved these potential issues, however are pleased we have been able to bring this forward.

“All companies have to be vigilant to defend against criminal cyber activity and we will continue to constantly review and strengthen our systems.”

In its own response, British Airways said it was “satisfied” it had systems in place to mitigate the issues raised by the Which? investigation.

“We take the protection of our customers’ data very seriously and are continuing to invest heavily in cybersecurity,” the airline said.

As it does with other security researchers, Marriott is taking a closer look at and addressing Which?’s findings, and would welcome a further dialogue with Which?’s technical experts at their earliest convenience

Marriott

“We have multiple layers of protection in place and are satisfied that we have the right controls to mitigate vulnerabilities identified. These controls are often not detected in crude external scans.”

Marriott said it had “embedded oversight and governance of its security and privacy programme at the highest level of its business” and continued to enhance its security and conduct regular tests of its systems.

“Marriott has conducted a preliminary review of Which?’s findings after Which? provided them to Marriott. At this stage, there is no reason to believe that the findings impact Marriott’s customer systems or data,” a company statement said.

“Marriott also notes that some of the findings are not attributable to Marriott, other findings could not be validated, others have already been addressed through compensating controls, and many of the findings relate to Marriott’s development environment – which contains limited applications and is not connected to Marriott’s customer systems or data.

“As it does with other security researchers, Marriott is taking a closer look at and addressing Which?’s findings, and would welcome a further dialogue with Which?’s technical experts at their earliest convenience.”

In their own response, Lastminute.com said it took a “robust risk-based approach” to its security structures and was “grateful” for the investigation’s research.

However, the company argued the examples highlighted by Which? were “mainly test sites containing no personal or sensitive data”.

American Airlines said it “recognises the importance of cybersecurity” and uses a range of tools to keep customers’ data safe.

It added it uses a “combination of internal and external cyber professionals to regularly identify and test the security of our systems and continue improving our capabilities”.

By Press Association

More Technology News

See more More Technology News

23andMe fined millions by watchdog after ‘profoundly damaging’ cyber attack exposing genetic data

23andMe fined millions by watchdog after ‘profoundly damaging’ cyber attack exposing genetic data

Scotland 2050 conference

‘Destructive’ social media will transform politics ‘for a generation’ – Forbes

View of Centre Court full of spectators watching a game at Wimbledon All England Lawn Tennis Club Championships. Wimbledon.

Wimbledon adopts AI for 2025 Championships with All England club introducing in-match analysis

Th new feature that lets you and a friend pair up and match with other pairs

Tinder launches 'double date' feature in bid to attract 'low pressure' Gen Z

An avocado bathroom suite built in the 70's.

Young homeowners ‘favour avocado bathrooms, relaxation zones and panelled walls’

Meta to introduce ads on WhatsApp as US tech giant reverses ‘no ads’ stance on world’s most popular messaging app

Meta to introduce ads on WhatsApp as US tech giant reverses ‘no ads’ stance on world’s most popular messaging app

Captain Cook's legendary ship has been discovered

Mystery of Captain Cook's lost ship solved after 250 years as scientists discover exact location of the HMS Endeavour

The ancient lost world was discovered in East Antarctica.

Lost world unearthed beneath Antarctica ice after 34 million years

Taoiseach Micheal Martin, Northern Ireland First Minister Michelle O’Neill and deputy First Minister Emma Little-Pengelly during the British-Irish Council (BIC) summit at the Slieve Donard resort in C

Leaders share healthcare and efficiency hopes for AI at British-Irish Council

Three and Vodafone

VodafoneThree promises better coverage at ‘no extra cost’ within months

The Khankhuuluu species weighed 750 kilograms, about the size of a horse

Newly discovered ‘Dragon Prince’ dinosaur rewrites history of T.rex

Aviation technology company Sita said 33.4 million bags were mishandled in 2024, compared with 33.8 million during the previous year.

Airlines lose fewer bags as tracking tech takes off as bosses say passengers expect similar service to a 'delivery app'

Social media app icons displayed on an Apple iPhone

Social media giants can ‘get on’ and tackle fraud cases, says City watchdog

Experts have warned about the risks posed by period tracking apps (Alamy/PA)

Experts warn of risks linked to period tracker apps

Data (Use and Access) Bill

Lords’ objections to Data Bill over copyright threatens its existence – minister

A primary school teacher looking stressed next to piles of classroom books

Pupils could gain more face-to-face time with teachers under AI plans