Data-breach

Breaches Will Keep Happening. Your Exposure Doesn't Have To.

Skyticket may have leaked 14.6 million records, then switched off saved credit cards, which is a lot like locking the barn once the horse is in another country. Three habits limit the damage the next time a company you trust gets hacked.

Between October 2 and October 4, someone got into the servers behind Skyticket, a Japanese travel booking site run by Adventure Inc. The company says about 14.6 million records may have been exposed: names, dates of birth, email addresses, and phone numbers.

That wasn't the only break-in. On September 20, a separate intrusion hit the company's business management system, and that one may have leaked more than 17,000 customer records that include bank account numbers people registered so they could get refunds.

Card numbers haven't been reported as exposed. But Skyticket has turned off saved credit cards on its site, which tells you how seriously they're taking the possibility.

And Skyticket isn't alone this week. The same Jiji Press report lists JR East (about 6.09 million accounts, through a ransomware attack on a cloud provider), Bookoff (up to 6.43 million members), and the company behind Big Echo karaoke (about 8.72 million customers). Four companies, more than 35 million records, one news cycle.

What a leak like this actually means for a family

A name, a birthday, an email address, and a phone number don't sound like much on their own. Together they're a starter kit. Someone can send an email that uses your real name, references a real trip booking, and looks just official enough to get a click. They can text your phone with the same story. A date of birth is still one of the questions a lot of companies ask to "verify" you.

The bank account numbers are worse. Those 17,000 people handed over account details for a good reason, to get their money back, and now that information sits wherever the attackers took it.

None of this was in the customers' control. Skyticket's servers got broken into, not their laptops. That's the part that bothers me most. You can do everything right on your end and still have your information walk out the door of a company you trusted with it.

What you can control is how much of you is sitting on those servers in the first place, and how far a leak can travel once it happens.

Use a forwarding email address for every site

Services like Apple's Hide My Email, Firefox Relay, DuckDuckGo Email Protection, and SimpleLogin give you a separate address for each site that forwards to your real inbox. If Skyticket leaks "skyticket-a7x2@relay.example", that's all they leaked. Your real address stays out of the dump.

It also gives you an early warning system. If a phishing email shows up at the address you only gave to one travel site, you know exactly where it came from, and you can shut that address off without touching anything else.

Use a unique password for every site

This breach doesn't mention passwords, but plenty of others do. If you reuse one password, a leak at one company turns into a key for your email, your bank, and everything else. A password manager makes this painless - it generates a long random password per site and remembers it so you don't have to. Turn on two-factor authentication wherever it's offered, especially on your email account, since that's the account that can reset all the others.

Don't save your card on someone else's server

Every site that offers to "remember this card for next time" is asking to keep a copy of your payment information on their servers. Skyticket shutting off saved cards after the fact is a good move, but the safer move is to never store it there.

Check out as a guest when you can. Type the card in each time, or use a wallet like Apple Pay or Google Pay that gives the merchant a token instead of your real number. Many banks and card issuers also offer virtual card numbers you can lock to a single merchant or delete after one purchase. A few extra seconds at checkout is a small price for not having to replace a card and update every autopay you have.

The same thinking applies to bank details. If a company offers to refund to your original payment method, take that over handing them a routing and account number.

If you've used Skyticket

Expect phishing. Skyticket's own advice is to watch for emails asking for passwords or card numbers and not to click the links in them. I'd add texts and phone calls to that list, since phone numbers were in the leak. If you registered a bank account for a refund, keep a close eye on that account and talk to your bank about what alerts they offer.

Breaches are going to keep coming. The goal is to make each one a non-event for your family - one throwaway email address to turn off, one password that doesn't unlock anything else, and no card sitting on a server you'll never see.

← All articles