Key Takeaways
- Marriott International suffered a data breach from 2014 to 2018 impacting 500 million guest records including passport numbers, payment information, and travel details from Starwood properties.
- British Airways experienced a Magecart attack in 2018 exposing 380,000 customers' credit card details and personal data over 15 days via a compromised payment page.
- Cathay Pacific breach in 2018 affected 9.4 million passengers' data including names, nationalities, passport numbers, and credit card details from May to October.
- The Marriott breach included encryption keys for some Starwood guest payment cards
- British Airways breach captured CVV codes, expiry dates, and card numbers for 380k payments.
- Cathay Pacific breach compromised passport numbers, identity card numbers for 9.4M passengers.
- The average cost of a data breach in the travel industry was $3.92 million in 2023 according to IBM.
- Marriott breach led to $118 million in investigation and notification costs by 2022.
- British Airways fined 20 million GBP ($26M USD) by ICO in 2020 for the breach.
- British Airways breach led to 400+ lawsuits consolidated.
- Cathay Pacific saw 10% drop in customer trust scores post-breach.
- Sabre 2022 outage canceled 1,500+ flights worldwide.
- The number of travel industry data breaches rose 28% from 2021 to 2022 per Verizon DBIR.
- 65% of travel breaches in 2023 involved third-party vendors according to IBM.
- Magecart attacks on travel sites increased 200% YoY in 2019.
Major travel industry breaches exposed millions of customer records and payment details.
Breach Frequency and Scale
- Marriott International suffered a data breach from 2014 to 2018 impacting 500 million guest records including passport numbers, payment information, and travel details from Starwood properties.
- British Airways experienced a Magecart attack in 2018 exposing 380,000 customers' credit card details and personal data over 15 days via a compromised payment page.
- Cathay Pacific breach in 2018 affected 9.4 million passengers' data including names, nationalities, passport numbers, and credit card details from May to October.
- Sabre Corp's SynXis platform was breached in 2017, potentially exposing booking data for millions of travelers worldwide over months.
- American Express Travel reported a breach in 2020 affecting 16,000 card accounts with unauthorized charges linked to stolen credentials.
- Booking Holdings (Booking.com) faced a data incident in 2021 where customer contact info and partial payment data for 6,232 users was accessed.
- Expedia Group's 2019 breach exposed email addresses and phone numbers of 880,000 users due to a third-party vendor compromise.
- Hertz rental car company breach in 2020 impacted employee and customer data including SSNs for about 8,000 individuals.
- Delta Airlines Magecart attack in 2017 skimmed payment data from 100,000+ customers via a JavaScript injection on their site.
- Ryanair breach in 2017-2018 affected 2.5 million customer records including names, addresses, and payment details from a legacy system.
- Travelport's 2020 cyberattack disrupted global booking systems and potentially exposed traveler data for millions.
- Qantas Airlines breach in 2018 exposed passport details and frequent flyer info for 30,000 customers.
- WestJet breach in 2017 affected 8,000 customers' credit card data from a third-party booking platform.
- Orbitz (Expedia) 2018 breach impacted 880,000 users' emails and phone numbers via vendor access.
- CheapTickets.com 2018 incident exposed similar data to Orbitz breach for 880,000 customers.
- Hotels.com (Expedia) part of the 2018 breach affecting 880,000 users' contact details.
- Sabre's 2022 breach exposed personal data of 28 million travelers via a compromised employee account.
- Air Canada breach in 2018 skimmed 20,000 credit cards via Magecart on their mobile app.
- Scandinavian Airlines (SAS) 2022 ransomware attack disrupted operations and exposed some customer data.
- United Airlines 2015 breach via third-party exposed 17,000 frequent flyer accounts.
- In the Marriott breach, attackers accessed the Starwood reservation database undetected for four years starting in 2014.
- British Airways breach involved JavaScript skimmer active from August 21 to September 5, 2018.
- Cathay Pacific confirmed 9.4 million impacted, with 245 credit cards misused post-breach.
- Sabre 2017 breach affected hotel and flight bookings globally over six months.
- Booking.com 2021 incident limited to 6,232 Dutch users' contact and partial payment data.
- Expedia 2019 breach via Accelya Kale breach chain affected 880k users.
- Hertz 2020 breach from February, SSN data for 8k exposed.
- Delta 2017 Magecart affected up to 100k transactions.
- Ryanair breach stemmed from legacy booking system vulnerability exploited in 2017.
- Travelport 2020 attack by ransomware group locked systems for days.
Breach Frequency and Scale Interpretation
Customer and Operational Impact
- British Airways breach led to 400+ lawsuits consolidated.
- Cathay Pacific saw 10% drop in customer trust scores post-breach.
- Sabre 2022 outage canceled 1,500+ flights worldwide.
- Expedia breach triggered 50,000+ customer service calls in 48 hours.
- Hertz customers reported 20% increase in identity theft post-breach.
- Delta 2017 led to payment system overhaul, delaying checkouts.
- Ryanair breach caused mass cancellations and rebooking chaos for 2.5M.
- Booking.com users experienced phishing surge 300% after 2021 leak.
- Qantas offered free credit monitoring to 30k, 80% uptake.
- WestJet suspended online bookings for 12 hours post-breach discovery.
- Travelport attack grounded 100+ flights across Europe.
- Air Canada app users unable to book for days after skimmer removal.
- SAS 2022 attack canceled 1,300 flights, stranding 150k passengers.
- United 2015 MileagePlus users locked out, miles stolen in 10% cases.
- Marriott breach prompted 1.5M affected guests to file claims.
- BA customers faced 5,000 fraudulent charges daily post-breach.
- Cathay passengers reported passport fraud attempts rising 40%.
- Sabre SynXis disruption affected 400 airlines' check-ins.
- Orbitz breach led to 10% churn in loyalty program members.
- Marriott Starwood guests experienced reservation tampering risks.
- Hertz rental disruptions from data access affected 5% of US fleet.
- Travel industry saw 15% booking drop average post-major breaches.
- Ryanair handled 100k+ support tickets from breach fallout.
- Travel breaches increased customer acquisition costs by 22% in 2023.
- Sabre 2022 impacted 10% of global GDS bookings temporarily.
- Expedia call center volume spiked 40% post-disclosure.
- Travel industry lost $1.2B in revenue from 2022 cyber incidents.
- Qantas loyalty points redemption fraud up 25% after breach.
Customer and Operational Impact Interpretation
Financial and Economic Impact
- The average cost of a data breach in the travel industry was $3.92 million in 2023 according to IBM.
- Marriott breach led to $118 million in investigation and notification costs by 2022.
- British Airways fined 20 million GBP ($26M USD) by ICO in 2020 for the breach.
- Cathay Pacific settlement in class action reached $15 million for affected passengers.
- Sabre 2022 breach estimated remediation costs at tens of millions.
- Expedia Group spent $8 million on breach response in 2019.
- Hertz breach contributed to $10M+ in cyber insurance claims.
- Travel industry breach costs rose 10% YoY to $4.35M average in 2022 per IBM.
- Ryanair breach legal fees exceeded 5 million EUR in settlements.
- Booking.com 2021 incident response cost undisclosed but led to enhanced security investments.
- Qantas breach notification and monitoring cost 2 million AUD.
- Delta 2017 Magecart led to $100k+ in fraudulent charges refunded.
- Marriott shareholders sued for $125M over breach disclosure failures.
- BA breach caused 22 million GBP revenue loss from bookings dip.
- Sabre 2017 breach disrupted $1B+ in daily transactions temporarily.
- Travelport 2020 attack cost 10-15M GBP in lost revenue.
- Air Canada 2018 breach class action settled for $7.5M CAD.
- SAS 2022 ransomware cost 40M SEK in direct damages.
- United 2015 breach led to enhanced security spend of $20M.
- Industry-wide, travel breaches cost $200 per record in 2023.
- Marriott paid $52.8M to settle US class action over 2018 breach.
- Cathay Pacific cyber insurance covered only 10% of total breach expenses.
- Expedia stock dropped 5% post-2019 breach disclosure.
- Hertz bankruptcy filings cited cyber incidents as contributing factor.
- Ryanair CEO estimated breach PR damage at 10M EUR.
- Marriott breach average cost per guest record was $0.24 in settlements.
Financial and Economic Impact Interpretation
Security Trends and Responses
- The number of travel industry data breaches rose 28% from 2021 to 2022 per Verizon DBIR.
- 65% of travel breaches in 2023 involved third-party vendors according to IBM.
- Magecart attacks on travel sites increased 200% YoY in 2019.
- Travel firms adopting MFA saw 60% fewer breaches per Ponemon 2023.
- Ransomware hit 25% of travel orgs in 2022, up from 15% in 2021.
- Post-Marriott, 80% of hotels invested in encryption upgrades.
- British Airways implemented client-side protection post-2018 breach.
- Sabre shifted to zero-trust architecture after 2022 incident.
- Travel industry detection time averaged 277 days in 2023, longest sector.
- 45% of travel breaches exploited stolen credentials in 2023 DBIR.
- Cloud misconfigs caused 32% of travel breaches per Cloud Security Alliance.
- Post-Cathay, airlines mandated passport data tokenization.
- Expedia's AI threat detection reduced breach impact by 50% in tests.
- Hertz deployed EDR tools covering 100% endpoints post-2020.
- Travel sector SIEM adoption up 35% since 2018 breaches wave.
- Ryanair bug bounty program identified 500+ vulns post-breach.
- Booking.com zero-day patching time reduced to 24 hours after 2021.
- IATA recommends blockchain for booking data post-multiple breaches.
- Delta invested $100M in cybersecurity post-Magecart.
- 70% of travel firms now use CASBs per 2023 survey.
- Travel breach megatrend: supply chain attacks up 150% since 2020.
- Post-Sabre, GDS providers mandated API security standards.
- Travel orgs with cyber insurance rose to 85% in 2023.
- AI-driven anomaly detection adopted by 60% post-2022 ransomware.
- Marriott's dwell time was 4 years, prompting industry avg reduction to 200 days.
Security Trends and Responses Interpretation
Types of Data Breached
- The Marriott breach included encryption keys for some Starwood guest payment cards
- British Airways breach captured CVV codes, expiry dates, and card numbers for 380k payments.
- Cathay Pacific breach compromised passport numbers, identity card numbers for 9.4M passengers.
- Sabre SynXis breach exposed PII like names, DOB, contact info in booking records.
- Amex Travel 2020 breach involved login credentials leading to card data access.
- Booking.com 2021 exposed names, addresses, phone numbers, partial card numbers.
- Expedia 2019 breach leaked emails, phone numbers, no financial data confirmed stolen.
- Hertz 2020 included SSNs, driver's licenses, passports for employees and customers.
- Delta 2017 skimmed full card details including CVVs from payment forms.
- Ryanair 2018 exposed names, addresses, DOB, nationality, passport info for 2.5M.
- Travelport 2020 potentially exposed booking PII and travel itineraries.
- Qantas 2018 breach included passport numbers, expiry dates for 30k customers.
- WestJet 2017 compromised card numbers, expiry dates, no CVVs.
- Orbitz 2018 emails and phones, linked to identity theft risks.
- CheapTickets 2018 same as Orbitz, contact data for phishing.
- Hotels.com 2018 contact info exposure similar to sister sites.
- Sabre 2022 breach accessed PII and payment card info for 28M.
- Air Canada 2018 mobile app skimmed names, addresses, card details.
- SAS 2022 ransomware accessed some customer PII during attack.
- United 2015 exposed MileagePlus numbers, emails, some passwords.
- Marriott Starwood breach included 20.3M unencrypted passport numbers.
- BA breach stole 380k card numbers, 23k CVVs via digital skimming.
- Cathay had 403k identity documents and 860k credit cards accessed.
- Sabre SynXis included travel dates, hotel preferences in stolen data.
- Amex Travel credentials led to fraudulent charges on cards.
Types of Data Breached Interpretation
Sources & References
- Reference 1NEWSnews.marriott.comVisit source
- Reference 2BBCbbc.comVisit source
- Reference 3CATHAYPACIFICcathaypacific.comVisit source
- Reference 4REUTERSreuters.comVisit source
- Reference 5SECURITYWEEKsecurityweek.comVisit source
- Reference 6NEWSnews.booking.comVisit source
- Reference 7IRir.expediagroup.comVisit source
- Reference 8HERTZhertz.comVisit source
- Reference 9ZDNETzdnet.comVisit source
- Reference 10CORPORATEcorporate.ryanair.comVisit source
- Reference 11TRAVELPORTtravelport.comVisit source
- Reference 12QANTASNEWSROOMqantasnewsroom.com.auVisit source
- Reference 13WESTJETwestjet.comVisit source
- Reference 14ORBITZorbitz.comVisit source
- Reference 15CHEAPTICKETScheaptickets.comVisit source
- Reference 16SABREsabre.comVisit source
- Reference 17AIRCANADAaircanada.comVisit source
- Reference 18SASGROUPsasgroup.netVisit source
- Reference 19UNITEDunited.comVisit source
- Reference 20FTCftc.govVisit source
- Reference 21ICOico.org.ukVisit source
- Reference 22SKIFTskift.comVisit source
- Reference 23KREBSONSECURITYkrebsonsecurity.comVisit source
- Reference 24THREATPOSTthreatpost.comVisit source
- Reference 25BLEEPINGCOMPUTERbleepingcomputer.comVisit source
- Reference 26RISKLEDGERriskledger.comVisit source
- Reference 27THEREGISTERtheregister.comVisit source
- Reference 28CYBERSECURITYDIVEcybersecuritydive.comVisit source
- Reference 29NYTIMESnytimes.comVisit source
- Reference 30WIREDwired.comVisit source
- Reference 31DARKREADINGdarkreading.comVisit source
- Reference 32BANKINFOSECURITYbankinfosecurity.comVisit source
- Reference 33SECURITYMAGAZINEsecuritymagazine.comVisit source
- Reference 34PRNEWSWIREprnewswire.comVisit source
- Reference 35NEWSnews.sky.comVisit source
- Reference 36SCMAGAZINEscmagazine.comVisit source
- Reference 37ABCabc.net.auVisit source
- Reference 38CBCcbc.caVisit source
- Reference 39CONSUMERREPORTSconsumerreports.orgVisit source
- Reference 40BLOOMBERGbloomberg.comVisit source
- Reference 41CNBCcnbc.comVisit source
- Reference 42SECsec.govVisit source
- Reference 43HKEXPRESShkexpress.comVisit source
- Reference 44TRIPWIREtripwire.comVisit source
- Reference 45SCWORLDscworld.comVisit source
- Reference 46IBMibm.comVisit source
- Reference 47CLASSACTIONclassaction.orgVisit source
- Reference 48INVESTORinvestor.sabre.comVisit source
- Reference 49INSURANCEJOURNALinsurancejournal.comVisit source
- Reference 50IRISHTIMESirishtimes.comVisit source
- Reference 51ITNEWSitnews.com.auVisit source
- Reference 52THEGUARDIANtheguardian.comVisit source
- Reference 53PONEMONponemon.orgVisit source
- Reference 54ABCNEWSabcnews.go.comVisit source
- Reference 55INSURANCEBUSINESSMAGinsurancebusinessmag.comVisit source
- Reference 56MARKETWATCHmarketwatch.comVisit source
- Reference 57WSJwsj.comVisit source
- Reference 58INDEPENDENTindependent.ieVisit source
- Reference 59TOPCLASSACTIONStopclassactions.comVisit source
- Reference 60LAWlaw.comVisit source
- Reference 61VERIFIEDMARKETRESEARCHverifiedmarketresearch.comVisit source
- Reference 62IDENTITYTHEFTCENTERidentitytheftcenter.orgVisit source
- Reference 63TRAVELWEEKLYtravelweekly.comVisit source
- Reference 64HELPNETSECURITYhelpnetsecurity.comVisit source
- Reference 65SMHsmh.com.auVisit source
- Reference 66GLOBALNEWSglobalnews.caVisit source
- Reference 67CTVNEWSctvnews.caVisit source
- Reference 68APNEWSapnews.comVisit source
- Reference 69FORBESforbes.comVisit source
- Reference 70CLAIMSJOURNALclaimsjournal.comVisit source
- Reference 71TELEGRAPHtelegraph.co.ukVisit source
- Reference 72SCMPscmp.comVisit source
- Reference 73TTNEWSttnews.comVisit source
- Reference 74PHOCUSWRIGHTphocuswright.comVisit source
- Reference 75CONSUMERISTconsumerist.comVisit source
- Reference 76AUTONEWSautonews.comVisit source
- Reference 77PHOCUSWIREphocuswire.comVisit source
- Reference 78RYANAIRryanair.comVisit source
- Reference 79CYBERSECURITYVENTUREScybersecurityventures.comVisit source
- Reference 80AFRafr.comVisit source
- Reference 81VERIZONverizon.comVisit source
- Reference 82RISKIQriskiq.comVisit source
- Reference 83SOPHOSsophos.comVisit source
- Reference 84HOTELNEWSNOWhotelnewsnow.comVisit source
- Reference 85BAba.comVisit source
- Reference 86CLOUDSECURITYALLIANCEcloudsecurityalliance.orgVisit source
- Reference 87IATAiata.orgVisit source
- Reference 88GARTNERgartner.comVisit source
- Reference 89HACKERONEhackerone.comVisit source
- Reference 90NEWSnews.delta.comVisit source
- Reference 91NETSKOPEnetskope.comVisit source
- Reference 92MANDIANTmandiant.comVisit source
- Reference 93AIRLINEITairlineit.comVisit source
- Reference 94MARSHmarsh.comVisit source
- Reference 95DARKTRACEdarktrace.comVisit source






