American Airlines Inc. on Tuesday confirmed a data breach and said while an “unauthorized actor” gained access to personal information of a small number of customers and employees through a phishing campaign, there was no evidence of data misuse.
Shares of the carrier, the latest U.S. company to suffer a cyber attack, fell 2.6% in afternoon trade. Recently, Uber Technologies Inc. and Take-Two Interactive Software Inc. also disclosed similar breaches, leaving investors and customers worried about data security.
Uber Says Lapsus$-Linked Hacker Responsible for Breach
“We are also currently implementing additional technical safeguards to prevent a similar incident from occurring in the future,” the airline said on Tuesday.
It discovered the breach in July and engaged a third-party cybersecurity forensic firm to conduct an investigation to determine the nature and the scope of the incident, according to a Sept. 16 consumer notification letter.
American Airlines has notified customers that personal information such as address, phone number, driver’s license number, passport number and/or certain medical information may have been accessed by the hacker, the letter showed.
“We regret that this incident occurred and take the security of your personal information very seriously,” Chief Privacy and Data Protection Officer Russell Hubbard said in the letter.
Was this article valuable?
Here are more articles you may enjoy.

Viewpoint: Who Gets Credit for Successful Renewal During Soft Reinsurance Market?
Former Insurance Agent Sentenced to Jail for Fraud, Again
Zurich CEO Says Staff Let Go as Regulator Finma Imposes Partial Sales Ban
Lemonade Posts $43M Loss for Q2 as it Continues to Grow Customer Base 

