[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3u2ltrgqz6fsb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":36,"seoTitle":37,"seoTitleEn":38,"seoDescription":37,"seoDescriptionEn":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"68e3266eda11adda48825291","MalindoAir","MalindoAir Data Breach","malindoair","malindoair.com","2019-03-01T00:00:00.000Z","2023-09-14T08:52:38.000Z","2026-07-18T23:53:49.822Z","Airline breach","https:\u002F\u002Ftheedgemalaysia.com\u002Farticle\u002Fmalindo-air-says-passengers-personal-data-may-have-been-compromised-breach",[15,17,18,19],"https:\u002F\u002Fvpnoverview.com\u002Fnews\u002Fmalindo-air-data-leak-reveals-info-of-60-million-passengers\u002F","https:\u002F\u002Fwww.lionairthai.com\u002Fen\u002Fpress_release\u002F2022\u002F04\u002F28\u002FREBRANDING-OF-MALINDO-AIR","https:\u002F\u002Fwww.batikair.com.my\u002F",4328232,"known",null,"unknown","Critical",[26,27,28,29,30,31,32,33,34,35],"Dates of birth","Email addresses","Genders","Loyalty program details","Names","Nationalities","Passport numbers","Phone numbers","Physical addresses","Salutations","\u003Cp>The MalindoAir data breach is a significant data security incident associated with former customer records of the Malaysian-based airline, which is now known under the Batik Air Malaysia brand, and is tracked as of March 1, 2019. The verified record contains 4,328,232 unique email addresses; within the broader customer records, there are also names, dates of birth, gender, nationality, phone numbers, physical addresses, passport numbers, salutation information, and loyalty program details. Such an airline breach produces a high impact not only in terms of account access but also concerning travel identity, booking fraud, fake customer service calls, and personalized phishing messages.\u003C\u002Fp>\n\u003Cp>In this record, the password or payment card field is not among the verified data types. Company statements indicated that payment information is not stored, and it was conveyed that passenger data may be associated with reviews in the cloud environment and on the e-commerce partner's side. This distinction is important: users should not panic as if their payment card information has definitely leaked, but they should consider that the combination of passport number, address, phone, and date of birth poses a strong risk in identity verification questions and travel-related fraud. MalindoAir records should therefore be carefully evaluated, especially by frequent travelers, loyalty program members, and those who use the same contact information across multiple services.\u003C\u002Fp>\n\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\n\u003Cp>The types of data confirmed in the MalindoAir breach consist of fields suitable for creating a passenger profile. Email addresses serve as entry points for targeted phishing messages; name, salutation, and gender information make these messages appear more realistic. Phone numbers can be used in scenarios such as fake reservation alerts via text message, fraudulent refund notifications, or notices of unclaimed tickets. Physical addresses and dates of birth can facilitate guessing identity verification questions.\u003C\u002Fp>\n\u003Cp>Passport number and nationality information are the most sensitive aspects of this record. These fields alone may not be sufficient to issue a new document in any country, but they can be used for identity impersonation, fraudulent travel support searches, visa consultancy scams, and account recovery attempts. Loyalty program details also help fraudsters personalize their messages, as they indicate the passenger's relationship with the airline and potential travel habits. Since password-verified fields are not included, the risk is more concentrated on the misuse of identity and travel information rather than password leaks.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope includes 4,328,232 unique email addresses, the breach date of March 1, 2019, and personal fields associated with airline customer records. The record contains dates of birth, email addresses, genders, loyalty program details, names, nationalities, passport numbers, phone numbers, physical addresses, and salutations. The added date is tracked as September 14, 2023; this date is not when the incident occurred, but when it was verified and added to the record list. This distinction is important to prevent users from confusing the 2023 or another publication date with the breach date.\u003C\u002Fp>\n\u003Cp>For this record, payment card, bank account, password, ticket payment amount, or health data is not considered a verified field. In statements from the company, it has been emphasized that payment information is not stored on servers. Nevertheless, the combination of physical address, phone number, date of birth, and passport number can pose a risk in identity verification processes. Therefore, the assessment should be limited to verified data fields; unconfirmed financial or password claims should not be presented to the user as if they were real.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The group at the highest risk consists of individuals who have traveled with Malindo Air, created a loyalty program account, or used the same email and phone information for other travel services. Frequent travelers are more likely to have their passport, nationality, and contact information used in multiple transactions, making them potential targets for fake reservation changes, fraudulent visa assistance, false baggage notifications, or excuses for flight cancellations. Corporate travelers also carry additional risk if their business email is associated with personal travel records.\u003C\u002Fp>\n\u003Cp>Users whose date of birth and physical address are recorded in the registration should be more cautious during account recovery and customer service verification processes. For users with a phone number, the risk of voice calls and text messages stands out. People with passport information should be more selective with messages related to passport renewal, visa application, border procedures, or travel insurance. It should not be assumed that every message comes from a real airline or official institution; before initiating any action, the domain name, phone line, and type of information requested should be checked separately.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who see a match in their MalindoAir record should first determine which email address was affected and check the airline, loyalty program, travel agency, and email accounts associated with this address. Even if the password is not a verified data field, if the password used for a Malindo Miles or similar travel account is also valid for other services, it should be changed to a unique password. Two-factor authentication should be enabled on email and travel accounts, and security alerts should be kept active.\u003C\u002Fp>\n\u003Cp>Affected individuals should regularly monitor their passport number, the validity of the passport, recent travel transactions, and official transaction notifications. Refunds for tickets, additional baggage payments, flight changes, or visa support messages from unknown contacts should not be responded to directly. Requests for verification codes received by phone, passport photos, or additional identification documents should be refused; if necessary, a separate session should be initiated from the known address of the airline or official institution. If any unusual transactions are observed in the financial area, the relevant bank or card provider should be contacted without delay.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Long-term protection for airline and travel accounts begins with using different passwords for different services. A password manager makes it easy to keep unique and strong passwords for each travel service. It is also useful to separate email addresses according to their purpose: the main email account can be for critical transactions, while travel and campaign registrations can be assigned to a separate address. This way, an airline breach does not turn into an event that affects the entire digital identity at once.\u003C\u002Fp>\n\u003Cp>The principle of data minimization is also important. Non-mandatory address, phone, or document fields should not be kept in the travel account; old reservations and unused loyalty memberships should be reviewed at regular intervals. In services that include passport information, unnecessary copies of documents should not be shared, and requests outside of official procedures should not be accepted. Since old airline violations, such as those by MalindoAir, can be used in fraud lists even years later, users need to develop a habit of regular account and communication security checks rather than a one-time check.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If there is a match in this record, first list your affected email address and the travel accounts opened with that address. Then check the security settings for your email account, airline account, loyalty program membership, travel agency account, and payment-linked services. If the same password is repeated on any account, change it immediately. If incoming messages request confirmation of passport, date of birth, address, or phone information, do not share information until separate verification through the official channel is completed, even if the message appears genuine.\u003C\u002Fp>\n\u003Cp>The MalindoAir data breach should be regarded not as a payment card or password leak, but as an airline customer record breach that contains extensive personal and travel identity data. Fields such as passport number, nationality, address, phone number, and date of birth may not change for a long time; therefore, the risk is not limited to the period close to the breach date. When a match is observed, the intention is not to create panic, but to be more selective in authentication processes, to strengthen old travel accounts, and to develop lasting vigilance against fraudulent reservation or document requests.\u003C\u002Fp>","","MalindoAir Data Breach (4.3 Million Reported Records)","MalindoAir Data Breach. 4.3 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmalindoair_com.webp",false,{"name":43,"sector":44,"country":45,"website":46,"websiteArchiveUrl":37,"websiteStatus":37,"websiteCheckedAt":22},"MalindoAir \u002F Batik Air Malaysia","Airline \u002F Travel","Malaysia","batikair.com.my"]