Delta Air Lines and Sears say hundreds of thousands of customers’ information may have been exposed

A Delta Air Lines jet sits at a gate at Hartsfield-Jackson Atlanta International Airport in October 2016.
(David Goldman / Associated Press)

Delta Air Lines, one of the world’s largest carriers, and retail giant Sears announced that payment information belonging to hundreds of thousands of their customers may have been compromised through an online chat service.

The service, operated by San Jose tech company [24], was compromised between Sept. 26 and Oct. 12, and information from customers of Delta, Sears and other corporate clients may have been accessed, according to statements by the companies.

The chat service appears on websites and allows passengers to type in questions and make reservations with replies provided by an automated system. At the airline, the information may have been breached when passengers manually entered data to make a payment transaction, according to representatives for the carrier.


“In the event any of our customers’ payment cards were used fraudulently as a result of the [24] cyber incident, we will ensure our customers are not responsible for that activity,” Delta said in a statement to passengers. It said malware “potentially exposed several hundred thousand customers.”

Sears issued a statement saying: “We believe this incident involved unauthorized access to less than 100,000 of our customers’ credit card information.”

Delta said that no passport, government ID, security or SkyMiles information was affected and that federal law enforcement officials were notified.

The chat-services provider also issued a statement, saying: “We are confident that the platform is secure, and we are working diligently with our clients to determine if any of their customer information was accessed.”

Computer glitches have been an ongoing problem in the airline industry in the last few years, some so severe that they have forced carriers to ground their planes or refrain from accepting new reservations.

In 2015, United Airlines requested a ground stop for all U.S. departures for nearly 90 minutes, blaming the problem on a failed computer network router that disrupted its reservation system.


That same year, United and American Airlines both announced that hackers had booked themselves free trips and upgrades by accessing the two airlines’ loyalty reward programs.

Japan Airlines reported in 2014 that the personal information of as many as 750,000 members of its loyalty rewards program may have been stolen by hackers.

To read more about the travel and tourism industries, follow @hugomartin on Twitter.


3:35 p.m.: This article was updated with Delta Air Lines saying malware “potentially exposed several hundred thousand” of its customers’ information.


This article was originally published at 12:10 p.m.