Investigation finds travel agent ‘design jam’ the cause of big Flight Centre data breach
![Abstract Technology Binary Code Dark Red Background. Cyber Attack, Ransomware, Malware, Scareware Concept](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
An investigation into a major data breach involving Flight Centre Travel Group (FCTG) more than three years ago has found that the company broke a number of Australian Privacy Principles.
In early 2017, FCTG organised a first-of-its-kind ‘design jam’ for March of that year, according to a recently published judgement by Australian Information and Privacy Commissioner Angelene Falk.
“The purpose of the event was to create technological solutions for travel agents to better support customers during the sales process,” Falk wrote.
“Sixteen teams, comprising 90 individuals, registered for and participated in the event.”
On 24 March 2017, Falk said FCTG provided event participants with access to a dataset for the 2015 and 2016 calendar years containing 106 million rows of data.
A file within the set contained 28 million rows of data from FCTG’s quoting, invoicing and receipting system. Falk said the data file contained 6,121,565 individual customer records.
Details known to contain personal information were obfuscated, leaving what was thought to be only the customer’s year of birth, postcode, gender, and booking information.
Representatives from FCTG reviewed a top 1,000-row sample of each data file within the dataset to ensure the data did not contain any personal information, according to Falk.
However, on 26 March 2017, an event participant notified FCTG that they had identified credit card information that was stored in an unstructured, free text field in the data provided to all event participants.
Falk noted in her case determination that by this time, the information had been available for approximately 36 hours.
“[FCTG] later identified that the customer information disclosed to the event participants mistakenly included details of 4,011 credit cards and 5,092 passport numbers for 6,918 individuals,” she wrote.
“Additionally, 475 usernames and passwords (mostly to vendor and supplier portals) and 757 rows containing customers’ date of birth were disclosed.”
FCTG claimed that it did not permit passport information and credit card details to be included in the free text field of its system.
Instead, the free text field was intended to be used by the company’s employees to communicate information about a booking.
However, Falk said that despite FCTG’s internal policies and training, the information showed that multiple travel consultants used the free text field to record customers’ credit card information and passport numbers from 1 January 2015 to 31 December 2016.
FCTG also acknowledged that at the time of the data breach, it had no technical controls to prevent or detect consultants entering inappropriate information into the free text field in its quoting, invoicing and receipting system.
On becoming aware of the data breach, FCTG said it had removed all access to the data by the event participants within 30 minutes of being notified, and obtained verbal confirmation after the event from each participating team that they had destroyed all copies of the data.
FCTG also conducted a post-incident review, including a business impact assessment and risk assessment.
Following the assessment, the company deemed the incident was ‘low risk’ because there was no intrusion into its systems, the incident was not the result of a malicious or deliberate act, the incident involved a ‘contained dataset’ provided to known third parties, there was no evidence of any actual misuse of the data, and confirmation was received from the third parties that the data had been destroyed.
FCTG also notified individuals whose passport or credit card details had been disclosed of the data breach on 7 July 2017, and offered free identity theft and credit monitoring coverage for 12 months.
The company said it paid the reasonable costs of passport replacement for customers who elected to do so, as well as notifying its merchant bank, with affected credit card details put on a fraud watch list.
FCTG also developed a remediation plan to address the cause of the data breach, based on its post-incident review, to prevent the occurrence of a similar incident.
Ultimately, Falk found that FCTG interfered with the privacy of approximately 6,918 of its customers by failing to take reasonable steps in the circumstances to implement practices, procedures and systems relating to its functions and activities.
However, the Information and Privacy Commissioner decided that further regulatory action was “not warranted” and “unnecessary in the circumstances”.
“The respondent submitted that it has taken remedial action since the data breach, no further similar incidents have occurred or are likely to occur, and significant time has passed since the data breach,” she wrote.
Falk also determined there was no evidence to support a declaration that FCTG redress any loss or damage suffered, or that any individuals are entitled to a specified amount by way of compensation.
“It is inappropriate for any further action to be taken in the matter,” she wrote.
In a statement to Travel Weekly, FCTG said it was “generally pleased” with the investigation’s findings and that no further action will be taken.
“The Flight Centre Travel Group takes data security and privacy issues very seriously,” the statement read.
“When this incident occurred three years ago, the company took immediate action to resolve the issue, which arose as a result of a human error, and to ensure it could not happen again.”
Featured image source: iStock/WhataWin
Email the Travel Weekly team at traveldesk@travelweekly.com.au
Angelene Falk data breach data privacy design jam event fctg flight centre flight centre travel group hackathon travel agentsLatest News
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Low-cost Indian carrier SpiceJet continues to burn cash
It’s not just low-cost Australian carriers that are facing hardship. SpiceJet, India’s version of Bonza, recently announced a 72 per cent reduction in its net loss versus last year. But, despite this improvement, the airline has posted losses for six straight years. But it has secured board approval to raise up to INR 30 billion […]
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
SAKA Museum recognised in TIME magazine’s World’s Greatest Places 2024
AYANA Resort Bali’s newly-opened cultural and events centre, SAKA Museum has been recognised in TIME magazine’s World’s Greatest Places list for 2024. Part of AYANA Bali’s resort destination, the museum integrates Bali’s rich history with state-of-the-art facilities, making it the centrepiece for the island’s spiritual and cultural heritage. TIME magazine’s inclusion of SAKA Museum in […]
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Journey Beyond launches first brand-led campaign during Paris Olympics
Journey Beyond is pushing the boundaries. On The Ghan, you can't even see them!
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Ascott Australia partners with Hotels for Trees
Hoteliers can take a 'Lyf' out of this book and improve their green credentials.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Victoria’s TAC Top Tourism Town Award winners for 2024
Keep looking in our own backyard. There are plenty of places to go.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Uniworld partners with Camilla Franks with Egyptian-inspired collection
We are in de-Nile about making puns combining Crocs and leopard prints, given this luxe partnership.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Aussies at Paris Olympics anxious about travel risks, with incidents already recorded
Fortunately one of our biggest gold medal hopes still held onto his pedals.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Banyan Tree Seaview Villas elevates Laguna Lang Co
If you've ever played golf in the tropics, start early. LIke way early. It's hot! Damn hot.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Silversea taps Barbara Biffi as senior vice president for global sales
Ultra-luxury and expedition cruise travel brand, Silverseas, has announced Barbara Biffi as its new senior vice president of global sales. Biffi joined the company in 2007, holding numerous positions and gaining a deep understanding of the brand, the preferences of its guests and its strategic goals, the company said. An Italian national with a wealth […]
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Wendy Wu unveils new Japan travel brochure and itineraries
Get outta town! Off-beat Japan will be a lot less congested we figure than the usual tourist hotspots.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
UK and Europe event organisers look to venues with sustainability integrity, ICC Sydney survey finds
Here in Sydney, you can even eat the table centrepieces. Although we advise they be cooked first.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Renos Rologas new general manager ANZ for FCM Travel
Two decades in the travel game! Let's hope Renos is in for the long haul at FCM.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Untamed Escapes to offer Cultural Day Tour from Port Lincoln in partnership with Maba Idi
International visitors travel thousands of kilometres for this experience. Time to share.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Luxe Finish Line Penthouses offer the best vantage point for the finish of the Sydney-Hobart
Long have we been following the yachts leavings Sydney Harbour and one day, we will see the finish, from this place!
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
In a busy world, proximity to nature is the new luxury
Forget Raffles, treat your nearest and dearest to a stay at the local campsite. They'll be super close to nature.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Circular Quay welcomes new Korean dining experience to Sydney Place
We once took Korean-American chef David Chang around Koreatown, Eastwood. Not happy about driving rain, loved the food.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
MSC Cruises unveils a new outdoor kid-friendly attraction on World America
Drop your kid down the jaws of a shark and they come out 11 decks below. Sounds good to me.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Amadeus welcomes FCM Travel as new reseller partner of Cytric Easy
Cytric Easy, the travel management tool embedded in Microsoft Teams, is to be integrated into FCM Travel portfolio. Amadeus and FCM Travel have extended their Cytric distribution agreement to include Cytric Easy. With this new agreement, global travel management company FCM Travel, becomes a reseller of the innovative travel management collaboration solution embedded into Microsoft […]
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Australian travellers abandon peer-to-peer stays and gravitate back to big hotels, survey finds
Doom scrolling Airbnb for the best-possible stay options two days out from departure was wearing us down, apparently.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Quark Expeditions launches the Ultimate Summer in the Arctic sweepstakes for travel advisors
Summer in the Arctic still means it's freezing. But hopefully a winning sweepstakes tickets will warm your cockles.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
‘I bet it smells weird’ – Internet divided over floating restaurant in China
I you are still feeling peckish at the end of your meal, their fish tank is full. But can you eat koi?
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
‘Turn up in the Northern Territory this Spring’ campaign deals
Agents and airlines get all hot and sweaty over these enticing deals. Or did someone just turn the air-conditioning up?
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
‘Like nothing on earth’: Saudi Arabia’s new Treyam resort set in a Star Wars-style landscape
As long as Jar Jar Binks is not there, we would like a seat at the Mos Eisley Cantina please.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Raffles Hotels and Resorts is set to open in Tokyo in 2028
Time to get your vision boards at the ready! Raffles is landing in Tokyo!
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
‘A true honour’ – Andrew Stark wins Flight Centre Director’s Award for the second time
Congratulations Andrew! If you're a fan of British reality TV you might notice a familiar face.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Club Med debuts travel agent portal 2.0 with bonus prize for tops sales
See those people by the pool. That could be you. Start selling through the portal people!
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Envoyage announces 2024 Australian Icons and rewards event in the Maldives
We were going to edit our name into the list but we chickened out.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
HIF Global signs collaboration agreement with Airbus on eFuels
We know it's a good thing but can a jet fuel geek out there send in a diagram explaining this please.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Crystal announces release dates for 2026 itineraries
If you have started collecting 2026 itineraries then here is another one for you.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Cairns Airport unveils display of support for FNQ youth
If you were craving some winter sun now you have a cultural reason for booking a flight to Cairns.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Viking announces six new cruise itineraries
Now's the time to start learning Putonghua, Nihongo and Lhasa. Or maybe even know where these are spoken.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Join Qatar Airways, Celebrity Cruises & Klook – Showcase Your Brand at Click Frenzy Travel August 2024!
Clicking calmly will also be welcome when it comes to this particular deal. Click calmly here to find out more.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
InsideAsia Tours launches new incentive that doubles agent commission
Double commission! We like the sound of that. Hope their system doesn't crash as a result.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Push to revive Parramatta’s iconic Roxy Theatre into entertainment destination
Long have we wished for this iconic heritage cinema to be revived as a tourist destination. Still waiting.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Qatar Airways signs an expansion to Boeing 777-9 aircraft order
Known as a quiet rural town in England, the entire global aviation industry now has its eyes on Farnborough.
![](https://www.travelweekly.com.au/wp-content/themes/bandtv1/img/default.png)
Flight Centre shares down following revised profit guidance
The stock market moves fast. What will the rest of the week hold for Flight Centre?