Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
At Cyber Management Alliance, Incident Response is our passion. We study and analyse cyber-attacks to create informational visual timelines which can be easily read for educational purposes and to enhance cyber resilience.
For the Easyjet cyber-attack, we have created a visual timeline and an accompanying detailed report. Download it now.
Check out our blog on the Easyjet Cyber Attack
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
In what easyJet described as a 'highly sophisticated' cyber attack, attackers gained unauthorised access to the airline's systems and reached the personal data of approximately 9 million customers. The email addresses and travel details of around 9 million people were accessed, and the credit card details of a smaller group of 2,208 customers were also compromised. easyJet said it became aware of the attack in January 2020 but only made it public in May 2020. The breach led to a major class-action claim and an ICO investigation, and is widely cited as one of the most significant UK airline data breaches.
easyJet said it became aware of the attack in late January 2020. Reporting indicated the accessed travel bookings spanned 17 October 2019 to 4 March 2020. The airline notified the small group of customers whose credit card details were affected in April 2020, and publicly disclosed the wider breach on 19 May 2020 after discussions with the Information Commissioner's Office (ICO). The legal and regulatory fallout - including a class-action claim - followed later in May 2020 and beyond.
No attacker was officially identified. Two sources with knowledge of the investigation told Reuters, on condition of anonymity, that the attack appeared to be part of a series attributed to suspected Chinese hackers, and that the same group had previously targeted travel records to track the movements of specific individuals rather than to steal card data for financial gain. easyJet itself declined to comment on who was responsible, so the China attribution remained suspected and unconfirmed.
easyJet characterised the incident as a 'highly sophisticated' cyber attack and said it had engaged leading forensic experts and closed off the unauthorised access. Reporting pointed to phishing as the likely method used to gain entry. easyJet did not publish full technical detail of the intrusion, so the precise attack chain was not officially confirmed beyond the company's 'highly sophisticated' description and the reported phishing vector.
According to easyJet's statements, the attackers accessed the email addresses and travel details of approximately 9 million customers. The travel details reportedly included information such as where customers were travelling from and to, departure dates, booking reference numbers, booking dates and the value of bookings, for journeys booked between 17 October 2019 and 4 March 2020. Separately, the credit card details of 2,208 customers were accessed. easyJet said passport details were not accessed.
Approximately 9 million customers had their email addresses and travel details accessed. Within that group, 2,208 customers had their credit card details compromised. easyJet said it would contact all affected customers, and that anyone who was not contacted could take it that their information had not been accessed by the attackers.
easyJet stated that passport details were not accessed in the breach. Credit card details were accessed for a specific group of 2,208 customers, who were notified in April 2020 and offered a dedicated helpline and 12 months of free credit monitoring. For the wider group of around 9 million customers, easyJet said the accessed data was limited to email addresses and travel details, not payment-card or passport information.
easyJet became aware of the attack in January 2020 but did not publicly disclose it until May 2020 - a gap of around four months that drew criticism. The airline said it took time to understand the scope of the attack and to identify who had been affected and what data had been accessed, and that it could only notify people once the investigation had progressed. It notified the smaller group of credit-card-affected customers earlier, in April 2020, before announcing the wider breach in May. Commentators and law firms argued the delay left customers exposed for longer than necessary.
easyJet said that as soon as it became aware of the attack it engaged leading forensic experts, informed the ICO and the National Cyber Security Centre (NCSC), and closed off the unauthorised access. It notified the 2,208 credit-card-affected customers in April 2020 with a dedicated helpline and 12 months of free credit monitoring, and - on the ICO's recommendation - contacted the approximately 9 million affected customers to warn them to be vigilant against potential phishing and any communications purporting to come from easyJet or easyJet Holidays.
easyJet faced a major class-action claim. On 22 May 2020, the law firm PGMBM issued a claim in the High Court in London under Article 82 of the EU GDPR, on behalf of affected customers seeking compensation for 'inconvenience, distress, annoyance and loss of control of their personal data'. The firm estimated a potential liability of up to £18 billion - which it suggested could equate to around £2,000 per affected customer - and more than 10,000 people reportedly joined the claim. That figure was the law firm's estimate of potential exposure rather than a confirmed award or regulatory fine, and the ICO opened its own investigation.
The Information Commissioner's Office (ICO) confirmed it had a live investigation into the attack. The National Cyber Security Centre (NCSC) said it was aware of the incident and had been working with easyJet from the outset to understand its impact on people in the UK, and advised anyone with potentially affected accounts to be especially vigilant against unusual bank-account activity and suspicious calls or emails, and to consider changing passwords for accounts that could have been affected. easyJet said it had informed both bodies as soon as it became aware of the attack.
The easyJet incident highlights several enduring lessons: people remain a primary attack surface, so phishing-resistant controls and security-awareness training matter; sensitive personal and travel data should be minimised, well protected and retained only as long as needed; and breach disclosure should be timely, transparent and well-rehearsed - the four-month gap between awareness and disclosure attracted significant criticism and legal action. It also shows how data breaches can lead to large-scale group litigation and regulatory scrutiny. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.