← Delta Air Lines

2024 Third-party MOVEit breach — 57k employee records

2024 57.0K records affected Share on X

Data compromised

Names, contact information, office locations

Technical writeup

Delta Air Lines acknowledged a data breach in November 2024 involving information from its internal employee directory. The breach exposed approximately 57,000 Delta employee records. The leaked data included names, contact information, and office locations. The breach was traced to a vulnerability in MOVEit file transfer software exploited in 2023. The stolen data originated from a third-party vendor holding Delta internal directory information.

Root cause

Third-party MOVEit vulnerability; vendor compromise.

References