Skip to main content
  1. Home
  2. Computing
  3. News

“Fraudsters” steal KLM customer data, here’s what they took and what to do about it

Add as a preferred source on Google
KLM Data breach
This is an AI-generated image created using Copilot / Ian Bell/Digital Trends

In a sky-high security slip-up, KLM Royal Dutch Airlines has admitted to a data breach where fraudsters sneaked into a third-party system, exposing customer details like names, contacts, and Flying Blue loyalty info. While passports and credit cards stayed safe, the incident echoes past airline hacks, leaving passengers on phishing alert.

What’s happened?

  • Breach confirmed: KLM and sister airline Air France revealed hackers accessed a third-party customer service platform, leaking personal data from recent interactions. KLM has not named the specific third-party vendor specifically, although they did state the third party vendor product was “on an external platform we use for customer service”.
  • Data exposed: Includes first and last names, contact details, Flying Blue numbers and tiers, email subject lines, and agent remarks—no financial or travel booking info was hit.
  • Swift action: KLM claims teams have contained the breach, beefed up defenses, and notified Dutch authorities per GDPR rules.
    A KLM spokesperson said: “We deeply regret any inconvenience this may have caused you,” stated Barry ter Voert, Chief Experience Officer, in emails sent out to customers

This is important because…

  • Supply chain vulnerabilities: Highlights risks in third-party vendors, a common weak link in breaches, as seen in the recent CrowdStrike fallout.
  • Phishing surge potential: Exposed data could supercharge scams, making fake KLM messages seem legit, per cybersecurity experts.
  • Industry pattern: Joins a string of airline hacks, like British Airways’ 2018 breach affecting 380,000 customers and Cathay Pacific’s massive 2018 data theft.

Why I should care?

  • Personal risk: If you’ve chatted with KLM support lately, your info might fuel targeted fraud—watch for dodgy calls or emails that might not make any sense.
  • Trust erosion: Breaches like this dent confidence in airlines, already battered by past incidents like Panasonic’s in-flight system hack.
  • Broader cyber threats: Reflects rising attacks on travel sector, with users on X reporting similar alerts and demanding compensation.

Ok, what’s next?

  • Stay vigilant: Scrutinize unsolicited KLM emails and phone calls; verify via official site or app before sharing more data.
  • Contact support: Hit up KLM’s Customer Contact Center for queries, as they advise in breach notices.
  • Industry push: Expect tighter regulations and AI-driven defenses, building on trends like CrowdStrike’s breach prevention tools.
  • Monitor updates: Follow KLM’s newsroom or cybersecurity hubs for developments, and check Digital Trends for similar stories like the Orbitz credit card hack.

The email sent to customers:

Dear XXXX,

Recommended Videos

We are reaching out to you because of a recent data breach involving your personal data. Specifically, a fraudster gained limited access to a third-party system that is used by KLM.

Our dedicated teams, together with the third-party system involved, quickly took the necessary steps to address the situation, and have reinforced protective measures to prevent this from happening again.

Data such as credit card details, passport numbers, Flying Blue Miles balances, passwords or booking information were not involved.

However, we have confirmed that some of your personal data were exposed by this breach. These relate to your earlier contact with our customer service and may include:
• Your first name
• Your family name
• Your contact details
• Your Flying Blue number and tier level
• The subject line of service request emails
• Remarks made by our customer service agents
We recommend staying alert when receiving messages or other communication using your personal information, and to be cautious of any suspicious activity. The data involved in this breach could be used to make phishing messages appear more credible. If you receive unexpected messages or phone calls, especially asking for personal information or urging you to take action, please check their authenticity.

We have reported this incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), in accordance with data protection laws.

We understand the concern this may cause, and we deeply regret any inconvenience this may have caused you. If you have any questions or need further assistance, please contact the KLM Customer Contact Center.

Yours sincerely,

KLM N.V.
Barry ter Voert

Chief Experience Officer & EVP Business Development”

Ian Bell
I'm the co-founder and CEO of Digital Trends Media Group, which I launched in 2006 out of my home office to share my passion…
Google is testing an AI-first homepage, and the Search button is reportedly taking a back seat
A quietly spotted redesign shows Google testing life without its own Search button.
Google Chrome with Gemini

For years, the Search button has been an integral part of the Google Search experience. However, right now, typing "google.com" into a browser is reportedly bringing up a new simplified layout that doesn’t include the Search button anymore (for a select group of signed-out users). 

It appears that the search giant is testing a new, AI-first layout with three dedicated buttons, which are new for traditional Google Search users, but familiar for those who use the Gemini chatbot on a regular basis.  

Read more
The FCC wants to ban some drones it already approved. Yeah, this is getting complicated.
FCC considers expanding drone restrictions to previously approved DJI models
dji drone

The US Federal Communications Commission is considering a move that could make things pretty awkward for drone buyers. The agency wants to expand its existing restrictions to cover certain drones with features such as LiDAR sensing, thermal imaging, and aerosol-dispersing systems. The weird part? Some of these drones were already approved for sale in the US.

In a report by DJI's own blog, this new development puts several DJI models in the spotlight, including the Air 3S, Avata 360, and Mini 5 Pro. Under the proposal, these drones could potentially be pulled from the US market, even though the FCC had previously cleared them. And no, if you already own one, the government isn't coming to take it away.

Read more
Hoy combines AirDrop, Loom, and voice messages in the Mac menu bar
The pre-release app lets Mac users send files, voice notes, and screen recordings without bouncing between separate tools
Person, Text, Electronics

Hoy wants sending something from your Mac to feel as casual as dropping a file onto someone’s desk. Instead of opening another app, you drag it onto that person’s face sitting in the menu bar.

https://twitter.com/heyiamdk/status/2082151995687748064

Read more