[News](/news)

Global airline network impacted by supply chain attack

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Global airline network impacted by supply chain attack

##### [Edward Kost](/team/edward-kost)

March 7, 2021

SITA, an IT systems vendor for 90% of the global aviation industry, has been used as an instrument for a sophisticated international supply chain attack.

Like all [supply chain attacks](https://www.upguard.com/blog/supply-chain-attack), the impact of this breach is likely to be proportional to the compromised vendor’s partner network, which isn’t good news for SITA.

SITA’s client base of over 400 airlines includes prestigious names like Qantas Airways, Qatar Airways, Pacific Airlines, American Airlines, NASA, Japan Airlines, United Airways, Emirates, and British Airways just to name a few. 

Potential victims are currently assessing their systems for evidence of compromise, but [Singapore Airlines has already announced](https://www.singaporeair.com/en_UK/sg/media-centre/news-alert/?id=kltm93p0) that around 580,000 of its customers have been impacted by this breach.

That’s over half a million customers impacted through a single partner -  SITA has over 400 of them.

SITA said in [their statement](https://www.sita.aero/pressroom/news-releases/sita-statement-about-security-incident/), that the breached data was located in U.S servers and that the data involved passenger information.

“SITA confirms that it was the victim of a cyber-attack, leading to a data security incident involving certain passenger data that was stored on SITA Passenger Service System (US) Inc. servers. Passenger Service System (US) Inc. (“SITA PSS”) operates passenger processing systems for airlines.” SITA said in their statement.

Supply chain attacks of this magnitude are not easy.

First, malicious code needs to be injected into a heavily guarded ecosystem. Then, the code needs to hide behind legitimate processes to prevent detection. Finally, a backdoor needs to be established to clandestinely exfiltrate all [sensitive data](https://www.upguard.com/blog/sensitive-data).

To motivate such a highly complex operation, the bounty needs to be valuable, and in SITA’s case, it definitely was. 

The SITA Passenger Service System (PSS) stores highly sensitive customer information including names addresses and passport data.

Because the SITA PSS ensures each airline can recognize the frequent flyer benefits of other airlines, the database was also storing alliance member data in addition to its customer data.

This attack further injures an industry already heavily wounded by Covid-19. 

Global flight frequency change dropped to -43% YoY in January 2021, and this trend is unlikely to aggressively invert anytime soon. Continuous mutations in the Covid-19 strain make the road to recovery long and its horizons misty.

Businesses currently experiencing a downturn are focused on survival and not cybersecurity. Cybercriminals know this and intentionally target such businesses while their backs are turned. \
\
Every industry, especially those experiencing a downturn, needs to start [monitoring its vendor network for security vulnerabilities](https://www.upguard.com/product/vendorrisk) that could be exploited in a supply chain attack.

## How secure is SITA?

SITA provides information technology and communications solutions for the air transport industry, serving airlines, airports, ground handlers, and government border agencies. The company offers systems for passenger processing, baggage handling, flight operations, border management, and air-to-ground communications.

* View our free preliminary report on SITA’s security posture
* 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

[View SITA's score](/security-report/sita)

[View score](/security-report/sita)

[https://www.sita.aero/](/security-report/sita)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

## Latest news

Stay up-to-date with the latest news in cybersecurity.

[](/news/hugging-face-data-breach-2026-07-20)

#### [Hugging Face data breach: key facts and what we know so far](/news/hugging-face-data-breach-2026-07-20)

A data breach involving Hugging Face was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 20, 2026

[](/news/ey-data-breach-2026-07-19)

#### [EY data breach: what happened and what's at risk](/news/ey-data-breach-2026-07-19)

A data breach involving EY was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

#### [South Florida Injury & Convenient Care data breach exposes names and Social Security numbers](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

A data breach involving South Florida Injury & Convenient Care was reported in July 2026. See incident details, impact on customers, and security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/park-west-psychology-data-breach-2026-07-16)

#### [Park West Psychology data breach: what happened and what's at risk](/news/park-west-psychology-data-breach-2026-07-16)

A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

#### [Fall River Municipal Credit Union data breach: what happened and what's at risk](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

A data breach involving Fall River Municipal Credit Union was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [](#)

July 14, 2026

[](/news/npcil-data-breach-2026-07-16)

#### [NPCIL data breach: World Leaks claims exposure of Kudankulam Nuclear Power Plant files](/news/npcil-data-breach-2026-07-16)

A data breach involving NPCIL was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 14, 2026

[View all news](/news)

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
