Latvia’s flag carrier airBaltic leaked passengers’ names, dates of birth, email addresses, and other details in emails sent to the wrong recipients due to a “technical error.”
Recently, several airBaltic customers took to social media to report that they received emails from the airline that contained the personal information of other travellers.
According to BleepingComputer, the data leak
compromised sensitive personal information like passengers’ names, dates of birth, email addresses, and more.
Acknowledging the issue, airBaltic said on Twitter that due to a technical issue, certain customers received incorrect emails containing the personal information of other travellers.
“We kindly inform you that due to technical issues a small number of our clients have received an e-mail with booking data relating to another passenger, not containing any financial or payment-related data.
“E-mail was sent out in language intended for the passenger whose data were included in the respective message, based on settings and language selection during the booking process,” the post
.
According to airBaltic, a very small number of passengers, 0.009% of those who booked tickets in 2023, were affected by the security incident. A spokesperson for the airline said, “We can confirm that on Friday, May 12, an internal technical problem was detected in the airBaltic e-mail distribution system, as a result of which a small number of passengers (approximately 0,009% of our clients this year) received an erroneous e-mail with the flight reservation information of another passenger.
“This email did not contain payment method or other financial details, or sensitive information. The protection of personal data is very important to us, thus we can guarantee that in the incident the personal information of the non-involved passengers is safe and the incident has been contained. We apologise for any inconvenience caused,” the spokesperson added.
Many affected passengers aired their concerns on social media over their travel reference numbers/PNRs being shared with others who could change their itinerary. Several passengers requested the airline to “simply change the booking reference.”
Acknowledging the passengers’ concerns, the airline spokesperson, said, “This has been done for passengers who contacted the airline individually and wanted it themselves.”
The airline is yet to clarify the kind of technical error it faced or the exact number of individuals affected by the security incident.