AWS Says Servers Secure Following Malindo Air Data Breach

Amazon Web Services (AWS) Singapore says all servers containing data of Malindo Air customers are secured "with no further vulnerabilities", and no payment details leaked. This confirmation follows a reported security breach that compromised personal data of 21 million passengers including that of Malindo's sister company, Lion Air. 

Forensic and data consultants also had been appointed to assess the overall data security infrastructure, focusing on passenger data protection across all platforms, said Malindo Air in a statement Thursday. In addition, it said remedial measures involving the notification of financial institutions, the police, and other relevant authorities had been established.

The airline reminded customers to be mindful of suspicious or unsolicited calls as well as email messages asking for verification of their personal data. 

The Malaysian carrier's announcement followed a previous statement confirming that data of its customers that were hosted on AWS' cloud platform might have been compromised. The cloud vendor, alongside Malindo Air's e-commerce vendor GoQuo, had begun investigating the breach.  

Malindo Air said it had put in place "adequate measures" that complied with Malaysia's Personal Data Protection Act to ensure its customer data were not compromised. The airline added that it did not store any payment details of on its servers and were compliant with the Payment Card Industry (PCI) Data Security Standard (DSS).

Members of Malindo Air's frequent flyer programme were further advised to change their passwords if they had used similar passwords on other online services. 

The security breach came to light when Kaspersky Lab last week pushed a tip to its cloud users in Thailand, alerting them to exercise caution when managing incoming email and text messages and calls. The Russian cybersecurity vendor said personal details belonging to passengers of Lion Group's Malindo Air and Lion Air had been posted in online forums and put on sale on the dark web. 

The breach reportedly was due to an unsecured AWS data bucket.  

Check Point Software Technologies's Asia-Pacific head of cloud security, Michael Petit, said in a note: "Data stored in cloud services like AWS S3 buckets are only as secure as their security configuration settings. Cloud services are convenient, but require proper configuration for the best security possible within the confines of such technologies. 

"Companies may have hundreds, thousands or even millions of S3 buckets or similar cloud data storage on other competing platforms. With such complexity of data storage in the cloud, it is imperative for companies to persistently audit and correct misconfigurations, as cloud services may also change their settings occasionally," Petit noted. "This is a necessarily laborious and time-consuming process for companies."

According to Check Point, personal data compromised in the breach included the passenger's date of birth, passport number, and mobile number.

RELATED COVERAGE

Lack of collaboration, disclosure affecting APAC security posture

Threat actors are collaborating more effectively than legit businesses in the region, which aren't sharing enough intelligence with others in the industry, says Microsoft Asia CSO.

Cyberattacks can cost APAC healthcare firms $23.3M

Healthcare organisations in Asia-Pacific can incur economic losses of up to US$23.3 million from cybersecurity incidents, though, 45% have either experienced or are not even sure if they have experienced a cyber attack.

APAC consumers have little trust in digital services

Just 31% of Asian consumers believe their personal data will be managed in a trustworthy way by businesses offering digital services, with 40% revealing their trust has been compromised whilst using such services.

One in four APAC firms not sure if they suffered security breach

A quarter of Asia-Pacific companies have experienced a security incident, while 27 percent aren't even sure because they haven't conducted any data breach assessment--even as the region is estimated to have lost US$1.75 trillion last year due to cyberattacks.

APAC firms look to edge for faster response but worry over data security

Edge computing is being sought out for faster response and cost savings, but there are concerns about security and latency when large volumes of data are processed on such platforms.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more