AirAsia Group was targeted by Daixin ransomware group that exposed 5M UNIQUE Passenger personal data, and all employee's personal data leaked.
The exposed information includes the date of birth, country of birth, where that person is from when employed for employees and the “secret question and answer” used to secure accounts.
The group claims that after encrypting its database and requesting an unspecified price to unlock it and reveal how it gained access to the network, it gave AirAsia a sample of the data.
In order to avoid encrypting or destroying anything that would be life-threatening, Daixin Team stated it had avoided locking up crucial files linked to flying equipment.
However, it has entirely restricted access to staff and passenger records until payment has been received.
Source: https://www.lowyat.net/2022/289084/daixin-airasia-hack-databreach/
TPRM report: https://scoringcyber.rankiteo.com/company/airasia
"id": "air1013221122",
"linkid": "airasia",
"type": "Ransomware",
"date": "11/2022",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"