CSIDB logo
Incident

Air France

Incident posture

Attack window
Jan 2023
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Air France
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Air France and KLM notified customers of unauthorized access to accounts within their shared Flying Blue loyalty program, which serves multiple partner airlines. Suspicious activity was detected and blocked, with corrective measures implemented to prevent further data exposure; impacted accounts were locked, requiring password resets. Compromised information included names, email addresses, phone numbers, recent transaction details, and loyalty points balances, but payment data, credit card numbers, and passport information were not accessed. The airlines confirmed reporting the incident to relevant data protection authorities and emphasized that no miles were fraudulently used due to timely intervention.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early January 2023, Air France and KLM detected unauthorized activity targeting customer accounts within their shared Flying Blue loyalty program, which serves multiple partner airlines including Transavia, Aircalin, Kenya Airways, and TAROM. Security teams identified suspicious behavior by an unauthorized entity, prompting immediate corrective measures to limit further data exposure. The airlines began notifying affected customers on or around January 6, 2023, confirming that personal information had been compromised. Exposed data included customer names, email addresses, telephone numbers, details of recent transactions, and Flying Blue-specific information such as accrued mileage balances. The breach did not compromise financial data such as credit card details or payment information, nor did it expose passport numbers. Customers reported receiving breach notifications through multiple channels, with some confirmation occurring via KLM's official Twitter account interactions.

Air France and KLM implemented containment measures including account locks for impacted users, requiring password resets through official airline websites to restore access. The airlines publicly stated that attackers were blocked before any loyalty miles could be fraudulently redeemed or transferred. Both organizations filed mandatory breach notifications with relevant data protection authorities in their respective countries. Impacted individuals were advised to monitor their accounts for suspicious activity despite assurances that sensitive data remained protected. The incident exclusively affected Flying Blue program members without disrupting core airline operations or reservation systems.

Sources

Sources available to members: 1 source.

CSIDB