Klook
| Primary URL | Location | Industry | www[.]klook[.]com |
Country
Hong Kong
|
Hospitality & Leisure
|
|---|
Profile
SOCIAPlus, also known by its alias SOCIAPlus, is a travel company headquartered in Hong Kong. The organisation operates primarily in the travel sector, providing services to customers through both a website and a mobile application. Its core business involves facilitating travel‑related transactions for users who book trips via its online platforms. The company serves a customer base that accesses its offerings through the website for desktop transactions and through the mobile app for on‑the‑go bookings. While specific figures on user count or annual revenue are not disclosed in the available sources, the organisation is recognised as a Hong Kong‑based player in the online travel market.
On June 29, 2018, SOCIAPlus experienced a data breach that was later reported by Latest Hacking News on July 2, 2018. The breach originated from malicious JavaScript code that had been injected into a third‑party analytics tool integrated into the company’s website. Attackers exploited this compromised script to gain unauthorized access to personal information and credit‑card details of customers who made transactions through the website during a multi‑month vulnerability window. Approximately eight percent of the customers who conducted website‑based transactions over that period were affected, while users who booked exclusively via the mobile application remained unaffected. Upon discovering the intrusion, SOCIAPlus contained the incident by removing the malicious code and subsequently engaged a cybersecurity firm to conduct a thorough investigation.
The company’s swift containment measures limited the exposure to website users only, preventing any impact on its mobile‑app‑based services. The incident highlighted the organisation’s reliance on third‑party components for website analytics and underscored the importance of monitoring external scripts for security vulnerabilities. SOCIAPlus’s handling of the breach—removing the offending code and enlisting expert forensic assistance—demonstrates a reactive security posture focused on incident mitigation and investigation. Although the breach affected a notable fraction of its web‑based clientele, no public reports indicate lasting regulatory penalties or long‑term service disruptions for the company. SOCIAPlus remains a Hong Kong‑based travel operator that continues to provide online travel services while having addressed the 2018 website security incident through remediation and external expertise.
