ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Travelocity exposes customer information

Troy Wolverton CNet

Published: 23 Jan 2001 14:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security breach at Travelocity exposed the personal information of thousands of the online travel company's customers, the company confirmed Monday.

Names, addresses, phone numbers and e-mail addresses of Travelocity customers who participated in a promotion on its site were exposed. Travelocity executives closed the breach, which involved an insecure directory, on Monday afternoon after it was pointed out.

For more than a month, up to 51,000 names could have been exposed by the breach, said Jim Marsicano, executive vice president of sales and service for Travelocity. Blaming the problem on human error, Marsicano stressed that no customer order information was compromised by the security hole.

"We take this privacy thing very seriously," Mariscano said. But he added, "In this case, we didn't do what we were supposed to do."

Although Travelocity is still investigating the incident, Marsicano said that it stemmed from the transfer of the company's servers from San Francisco to Tulsa last month. As part of the move, some of the company's internal data from two promotional contests that ran last year was inadvertently left on a computer that is now being used as a Web server, he said.

"We had a weak link in this particular transaction and you see the end result," he said. These kinds of breaches occur when a company gets complacent about security risks, said Richard Power, editorial director of the Computer Security Institute.

"This is an error (of) not dotting their I's or crossing their T's," Power said. "This is a situation where they are probably understaffed, or they haven't understood that they are at risk of somebody poking around."

There have been a series of online break-ins recently.

Last month, a hacker broke into Egghead.com, potentially exposing its 3.7 million customer accounts. Weeks later, the company later said that the hacker didn't gain access to any of the credit card numbers it had on file, but by then many of the credit cards had been canceled by banks or worried customers.

Earlier last year, security breaches or hacker attacks exposed customer and client information at CreditCards.com, Eve.com, IKEA and Amazon.com.

An e-commerce executive, who asked to remain anonymous, reported the security hole to CNET News.com on Monday. The insecure directory allowed anyone to see the customer data without a password.

Travelocity's Web site assures customers of the site's security, saying it uses "the latest encryption technology to ensure that every transaction is safe." The company said it encrypts all personal information after it is entered, transmits the encrypted information over the Internet to a secure server, where it is translated back to its original form and stored in an off-line database.

Simple errors like the Travelocity breach have happened all too frequently, said Jason Catlett, president of the spam-fighting group Junkbusters. They stem from companies not devoting enough financial resources and technical expertise to addressing security issues, he said.

"Of course these mistakes shouldn't happen," Catlett said. "There's a rush to be first with a new feature and to get the promotion running rather than making sure all of the doors are locked before they open the front gate."

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
33 out of 58 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Project Manager sought by Top Tier Investment Bank

A Top Tier Investment Bank requires a new Project Manager to work within the Transaction Services area of the business, located in the Docklands area ...

Excellent Opportunity! 2nd Line Support Engineer-Hertfordshire- 24k

My client is the leading provider of data communications services for transaction-orientated applications and are currently recruiting for a Support ...

SQL Server Production DBA, leading financial company, Projects!

An leading Investment Bank is seeking an intelligent SQL Server DBA to join the team, supporting large numbers of servers and working on various ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains