← Case Files · The Breach Files

2021 · Aviation

Air India, 2021: ten years of passengers, lost by a supplier

Case file · 3 min read · Published 14 September 2026

People affected
about 4.5 million passengers
When it happened
February 2021
Made public
21 May 2021
How they got in
Compromise of SITA Passenger Service System, a shared platform used by many airlines
Attributed to
Not publicly identified

What was exposed: Names · Dates of birth · Contact details · Passport information · Ticket information · Frequent flyer data · Some payment card data, without CVV

In May 2021, Air India told 4.5 million passengers that their data had been taken — names, dates of birth, contact details, passport information, ticket data and frequent flyer records, covering everyone who had travelled with it between August 2011 and February 2021. The intrusion had not happened at Air India. It happened at the company that runs the reservation platform.

What happened

SITA is an air transport technology provider. Its Passenger Service System handles reservations, ticketing and passenger processing for a large number of airlines, which is why carriers do not each build their own: the industry runs on shared infrastructure that has to interoperate across every airline, airport and alliance in the world.

SITA disclosed a security incident affecting that platform in early 2021. Airlines then worked out, individually, what data of theirs had been held there. Air India's notification followed in May, describing roughly 4.5 million affected passengers and a ten-year window of data. Several other carriers, including members of the same alliance, made their own disclosures.

The disclosure gap is structural, not evasive. The supplier detects the intrusion and tells its customers. Each customer then has to determine which of its own records were in the affected systems, in what fields, for which people, under which country's notification rules. That takes weeks even when everyone is competent and cooperative — which is why supply-chain breach notifications reach the people affected so much later than platform-level ones.

The retention multiplier

The most consequential number in this case is not 4.5 million. It is ten years.

A passenger who flew once in 2012 and never again was in this breach. Their passport number, date of birth and contact details were retained by a system serving an airline they had used once, nearly a decade earlier, because nothing in the process ever decided those records should expire.

Airlines have real reasons to keep some history: loyalty programmes, dispute handling, regulatory requirements for passenger data. None of those reasons require a full passport number for a journey completed nine years ago. The gap between "we have a reason to keep something" and "we keep everything" is where most of the avoidable exposure in this archive lives.

Why travel data is worth more than it looks

  1. Passport numbers are durable identifiers. Valid for up to a decade, accepted as proof of identity, and awkward and expensive to replace.
  2. Itineraries reveal patterns. Where someone goes, how often, with whom they are booked — a profile that supports both targeted fraud and physical tracking.
  3. Loyalty accounts hold value directly. Air miles are stolen and laundered through award bookings, and account takeovers of frequent flyer programmes are a small industry.
  4. Travel context makes phishing work. A message about a real booking reference, sent near a real travel date, defeats most people's scepticism.

The shared-platform problem

This case belongs in the same category as MOVEit: the target is not the organisation whose customers suffer, but a platform many organisations depend on. Aviation is unusually concentrated in this respect — a handful of providers handle reservations, departure control and baggage systems for most of the world's carriers, because interoperability demands it.

The trade-off is not resolvable by any single airline. Shared infrastructure is the reason a ticket bought in one country works on a partner airline in another, and it is also the reason one intrusion reaches passengers of many carriers at once. What an individual airline can control is what it puts into that shared system and how long it leaves it there.

If you flew before 2021

  1. Check whether the passport in question is still valid. If you have renewed since, the exposed number no longer authenticates anything.
  2. Change frequent flyer passwords and enable two-factor authentication. Loyalty accounts are directly monetisable and are attacked constantly.
  3. Treat booking-related messages with suspicion. Verify through the airline's app or website rather than a link — what distinguishes a real travel notice from a good imitation.
  4. Ask airlines and hotels to delete what they no longer need. Data protection rights differ by country, but the request costs nothing and the retention default is otherwise forever.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Who is SITA and why did an airline breach start there?

SITA is an air transport technology provider whose Passenger Service System handles reservations and passenger processing for many airlines worldwide. Airlines rely on shared platforms like it rather than each building their own. When one such platform is compromised, the passengers of every airline using it are exposed at once — Air India was one of several carriers affected by this incident.

How far back did the data go?

Air India said the compromised data covered passengers registered between August 2011 and February 2021 — roughly ten years. Long retention is the quiet multiplier in breaches like this: the intrusion lasted weeks, and the damage covered a decade.

Was payment card data included?

Some card data was reported as affected, but Air India stated that CVV and CVC security codes were not held by it. Passport information is the more durable concern, since a passport number stays valid for years and supports identity fraud in ways an expiring card does not.

What should affected passengers do?

Change frequent flyer passwords, particularly if reused; watch for travel-themed phishing that references real bookings; and be alert to identity verification requests that quote passport details. Where a passport has since been renewed, the risk from the old number falls away naturally.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →