Cathay Pacific
Disclosed Oct 24, 20187 years ago9,400,000 affectedSettled
Breach exposed 9.4M passengers' data; ICO fine of GBP 500,000
Attackers entered Cathay Pacific systems via an internet-facing server as early as October 2014 and installed malware to harvest data, exposing names, passport and ID details, birth dates, contact details and travel history of about 9.4 million customers, 111,578 of them in the UK. The ICO imposed the maximum GBP 500,000 fine.
What is known
| People affected | 9,400,000 (as reported by the organization) |
|---|---|
| Disclosed | Oct 24, 2018 |
| Discovered | Mar 2018 |
| Attack | Hacking |
| Data exposed | Names, Government IDs, Dates of birth, Phone numbers, Emails, Addresses, Payment cards, Other |
| Sector | Transport · HK |
| Status | Settled |
| Lawsuit or fine | GBP 500,000 ICO fine (March 2020) (about $640K) |
Sources
| Source | |
|---|---|
| PCPD Media Statement: Cathay Data Breach Incidentpcpd.org.hk · Regulator | Regulator |
| Cathay Pacific says 9.4M passenger records affected by data breachtechcrunch.com · News | News |
| Cathay Pacific fined GBP 500k by UK's ICO over data breach disclosed in 2018techcrunch.com · News | News |
Notices filed
History of this record
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · fine_usd: empty to 640000 · seed source
- 2026-09-25 · lawsuit: empty to GBP 500,000 ICO fine (March 2020) · seed source
- 2026-09-25 · data_types: ["names","government-id","dob","phone","emails","addresses","payment-card"] to ["names","government-id","dob","phone","emails","addresses","payment-card","other"] · seed source
- 2026-09-25 · discovered: empty to 2018-03 · seed source
- 2026-09-25 · summary: Hong Kong's Privacy Commissioner found that Cathay Pacific and Dragonair failed to protect personal data of about 9.4 million passengers accessed without authorization, citing weak vulnerability management and data governance. to Attackers entered Cathay Pacific systems via an internet-facing server as early as October 2014 and installed malware to harvest data, exposing names, passport and ID details, birth dates, contact details and travel history of about 9.4 mil · seed source
- 2026-09-25 · title: Unauthorized access to data of about 9.4 million Cathay passengers to Breach exposed 9.4M passengers' data; ICO fine of GBP 500,000 · seed source
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.