Menu
Browse

Cyber Incident Victim: SOCIAPlus

Date:

Jun 2018

Location:

Hong Kong

Summary

A Hong Kong-based travel company experienced a data breach when attackers exploited malicious JavaScript code linked to a third-party analytics tool integrated into its website. The compromise exposed personal information and credit card details for approximately 8% of customers who conducted transactions via the website over a multi-month period, though mobile app users remained unaffected. The company contained the incident upon discovery, removed the malicious code, and engaged a cybersecurity firm to investigate. Unauthorized access occurred through the compromised third-party script, impacting website transactions during the vulnerability window before mitigation.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On June 29, 2018, Hong Kong-based travel booking platform Klook notified customers of a data breach resulting from unauthorized access to its systems. The compromise occurred via a malicious JavaScript code linked to SOCIAPlus, a third-party web analytics tool integrated into Klook’s website. Attackers exploited this code to extract customer data between December 11, 2017, and June 13, 2018. Klook confirmed the breach originated from the infected SOCIAPlus script after coordinating with the third-party provider. Investigations estimated approximately 8% of Klook’s customer base was affected, with compromised data including personal details and credit card information. Only users who conducted transactions through Klook’s website during the exposure window were impacted; mobile app users remained unaffected. The company contained the breach upon detection but acknowledged data exfiltration had already occurred during the active intrusion period.

Cyber Incident Image

Klook engaged cybersecurity firm Kroll to investigate the incident and removed the malicious JavaScript from its platform. The company issued direct notifications to affected users and publicly confirmed the breach was contained. While declaring the threat resolved, Klook advised customers to monitor financial accounts for suspicious activity and reset their platform passwords as a precaution. Internal assessments confirmed the breach’s scope was limited to web transactions during the six-month exposure window, with no evidence of ongoing system compromise after June 13, 2018. Klook’s response emphasized transparency through FAQs and a press release detailing the intrusion vector and remediation steps.

Sources
Sources available to members
1 source