skyticket May Have Leaked Personal Information in Unauthorized Access

skyticket May Have Leaked Personal Information in Unauthorized Access

Adventure announced on October 9 that its reservation website, “skyticket,” had been subject to unauthorized access by a third party, potentially resulting in the leak of users’ personal information.

Three incidents were discovered: unauthorized access to servers, unauthorized access to a business management system, and the viewing of reservation information through its bus booking service.

The unauthorized server access occurred between October 2 and 4 and was discovered on October 5. Some skyticket administrative functions were improperly operated, allowing access to data stored on other servers and in the cloud. Approximately 14.64 million records were affected, including login passwords for approximately 4.13 million members. The potentially leaked information included names (including passport spellings), dates of birth, email addresses, telephone numbers, postal codes and addresses, remitter names for bank transfers, and hashed login passwords.

The unauthorized access to the business management system occurred on September 20 and was discovered on September 28. The incident exploited a system vulnerability and affected 17,780 records. Information including names, telephone numbers, and bank account details for refunds (financial institution name, branch name, account type, account number, and account holder name) was leaked or may have been leaked. Some records also included email addresses and dates of birth (68 records), addresses (18 records), and other information. Separately, the company confirmed unauthorized login to one member’s account on September 9.

The viewing of reservation information in the bus booking service occurred between August 3 and October 1 and was discovered on October 1. Bus reservation completion pages could be displayed without logging in and were systematically viewed by a third party. Approximately 12,000 reservations were affected. Information that was viewed or may have been viewed included the booker’s name (in kana), age, gender, date of birth, email address, telephone number, member ID, type of device used to make the reservation, payment method and amount, reservation date and time, details of the bus service, and the names, ages, and genders of accompanying passengers.

No secondary damage has been confirmed at this time, except for the unauthorized login to one member’s account in the second incident. However, the company warned of potential risks including fraudulent emails, SMS messages, phone calls, and postal mail impersonating the company, financial institutions, airlines, or bus operators; unauthorized logins if passwords are cracked; attempts to obtain bank account information under the guise of refund procedures; and communications requesting reservation changes or cancellations, or payment of additional charges. The company does not store credit card numbers or passport images, and stated that neither was leaked in any of the incidents.

The company has already blocked the route used for the unauthorized access and implemented measures to address the vulnerabilities. It has suspended payments using stored credit cards and the function for saving card information. It has also reported the matter to Japan’s Personal Information Protection Commission.

Users are being urged to change their passwords and check their reservation history in My Page, as well as their credit card statements.

Notice
This article was generated using automatic translation by GPT-4 API.
The translation may not be accurate.