2024 Third-party MOVEit breach — 57k employee records
Data compromised
Names, contact information, office locations
Technical writeup
Delta Air Lines acknowledged a data breach in November 2024 involving information from its internal employee directory. The breach exposed approximately 57,000 Delta employee records. The leaked data included names, contact information, and office locations. The breach was traced to a vulnerability in MOVEit file transfer software exploited in 2023. The stolen data originated from a third-party vendor holding Delta internal directory information.
Root cause
Third-party MOVEit vulnerability; vendor compromise.