Advertisement
Promo

Online business Toolkit

Travelocity exposes customer information

Troy Wolverton CNet

Published: 23 Jan 2001 14:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security breach at Travelocity exposed the personal information of thousands of the online travel company's customers, the company confirmed Monday.

Names, addresses, phone numbers and e-mail addresses of Travelocity customers who participated in a promotion on its site were exposed. Travelocity executives closed the breach, which involved an insecure directory, on Monday afternoon after it was pointed out.

For more than a month, up to 51,000 names could have been exposed by the breach, said Jim Marsicano, executive vice president of sales and service for Travelocity. Blaming the problem on human error, Marsicano stressed that no customer order information was compromised by the security hole.

"We take this privacy thing very seriously," Mariscano said. But he added, "In this case, we didn't do what we were supposed to do."

Although Travelocity is still investigating the incident, Marsicano said that it stemmed from the transfer of the company's servers from San Francisco to Tulsa last month. As part of the move, some of the company's internal data from two promotional contests that ran last year was inadvertently left on a computer that is now being used as a Web server, he said.

"We had a weak link in this particular transaction and you see the end result," he said. These kinds of breaches occur when a company gets complacent about security risks, said Richard Power, editorial director of the Computer Security Institute.

"This is an error (of) not dotting their I's or crossing their T's," Power said. "This is a situation where they are probably understaffed, or they haven't understood that they are at risk of somebody poking around."

There have been a series of online break-ins recently.

Last month, a hacker broke into Egghead.com, potentially exposing its 3.7 million customer accounts. Weeks later, the company later said that the hacker didn't gain access to any of the credit card numbers it had on file, but by then many of the credit cards had been canceled by banks or worried customers.

Earlier last year, security breaches or hacker attacks exposed customer and client information at CreditCards.com, Eve.com, IKEA and Amazon.com.

An e-commerce executive, who asked to remain anonymous, reported the security hole to CNET News.com on Monday. The insecure directory allowed anyone to see the customer data without a password.

Travelocity's Web site assures customers of the site's security, saying it uses "the latest encryption technology to ensure that every transaction is safe." The company said it encrypts all personal information after it is entered, transmits the encrypted information over the Internet to a secure server, where it is translated back to its original form and stored in an off-line database.

Simple errors like the Travelocity breach have happened all too frequently, said Jason Catlett, president of the spam-fighting group Junkbusters. They stem from companies not devoting enough financial resources and technical expertise to addressing security issues, he said.

"Of course these mistakes shouldn't happen," Catlett said. "There's a rush to be first with a new feature and to get the promotion running rather than making sure all of the doors are locked before they open the front gate."

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
33 out of 58 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters