TRANSPORTATION BUSINESS - KUALA LUMPUR. Indonesian Lion Group's Malaysian subsidiary Malindo Air said on Monday that two former employees of its e-commerce contractor were responsible for its passenger data breach.
Malindo Air made the breach public last week after Moscow-based cybersecurity firm Kaspersky Lab said in a report that the details of around 30 million passengers of Malindo and another Lion Group subsidiary Thai Lion Air were posted in online forums.
Read Also: Data pribadi penumpang bocor, Kominfo minta Lion Air Group lakukan pengamanan
Kaspersky said parts of the leaked databases were up for sale on the dark web.
Malindo Air said in a statement that two former employees of e-commerce services provider GoQuo (M) Sdn Bhd in their development centre in India "improperly accessed and stole the personal data of our customers".
The airline said the data breach has since been contained and the matter has been reported to the police in Malaysia and India.
Read Also: Data pribadi dari jutaan penumpang anak usaha Lion Air bocor?
Malindo Air also said the breach was not related to the security of cloud service provider Amazon Web Services' data architecture, and none of the payment details of customers were compromised.