The Air India Passenger Data Breach
A cyberattack on Air India's foreign passenger-data processor exposed a decade of passport, payment card and frequent-flyer details for 4.5 million travellers. Five years on, no regulator has fined Air India and no criminal prosecution over the breach has been publicly reported.
The Promise
โWe take data privacy very seriously and have taken all steps to secure the personal data of our customers.โ
โ Air India, India's flag-carrier airline, then still government-owned, disclosing the breach to affected passengers ยท 21 May 2021
Statement made in Air India's public notification to customers after the scale of the SITA breach became clear.
The Standard
That passenger personal data โ names, dates of birth, contact details, passport numbers, ticket information and payment card data โ held by Air India and its ticketing infrastructure provider would be kept secure against unauthorised access.
Information Technology Act, 2000 and its reasonable-security-practices rules, which require body corporates handling sensitive personal data to maintain reasonable security safeguards.
In force from 1 February 2021
The Reality
Air India disclosed on 21 May 2021 that a cyberattack on SITA, the Switzerland-based passenger-service-system provider used by Air India and dozens of other airlines, had compromised personal data of about 4.5 million Air India passengers registered between August 2011 and February 2021. Exposed data included names, dates of birth, contact information, passport details, ticket information, and Star Alliance and Air India frequent-flyer program data; some payment card details were also affected, though CVV numbers and passwords were not exposed. Air India said it had secured its systems, engaged external specialists, notified banks and reset frequent-flyer passwords, but as of this entry's writing no Indian regulator is known to have issued a public penalty against Air India over the incident, and no criminal case specific to the Air India breach has been widely reported.
As of 21 May 2021
The Gap
Bars share a single zero-based scale. No axis truncation is used to exaggerate or minimize the gap between the two figures.
Timeline
- MilestoneSITA's servers are hacked
Attackers compromise passenger-service-system servers operated by SITA, used by Air India, Singapore Airlines, Lufthansa, Malaysia Airlines, Cathay Pacific and other carriers.
- AnnouncementAir India first informs passengers of the SITA attack
Air India acknowledges the SITA cyberattack but does not yet detail the scale of the impact on its own passenger data.
- RevisionFull scale of the breach disclosed
Air India confirms personal data of about 4.5 million passengers registered over nearly a decade was compromised.
- StatusAir India response measures announced
Air India says it secured affected servers, engaged external cybersecurity specialists, notified banks and reset frequent-flyer passwords.
Legal Status
No public record of a regulatory fine or criminal prosecution specific to the Air India SITA breach has been identified as of this entry. The matter remains without a disclosed formal legal resolution in India.
Verdict
A real, large-scale, independently confirmed breach of Indian airline passenger data โ spanning nearly a decade of records for 4.5 million people โ for which no public accountability outcome (fine, penalty or prosecution) specific to Air India has been reported since 2021.
The breach and its scale are corroborated by multiple independent outlets (Bleeping Computer, TechCrunch, Forbes, The Record) as well as Air India's own customer notification; the absence of a subsequent regulatory or criminal resolution is based on the lack of reporting on one, which is a negative claim and could change if action is later disclosed.
What remains incomplete
- This entry cannot confirm with certainty that no regulatory or contractual penalty was ever privately imposed on Air India or SITA โ only that none has been publicly reported.
- India's Digital Personal Data Protection Act was not yet in force at the time of this breach, so the applicable Indian legal framework was limited to IT Act rules; this entry has not independently verified whether IT Act enforcement action was taken.
- The exact number of Indian passengers (as distinct from the global total of 4.5 million) affected has not been separately confirmed.
Sources
Related investigations
The 2G Spectrum Allocation Case
The CAG put the loss from underpriced telecom licences at โน1.76 lakh crore, once the country's most-quoted corruption figure. A decade later, a special court acquitted every single person accused of the underlying crime.
The GainBitcoin Cryptocurrency Ponzi Scheme
GainBitcoin promised investors 10% monthly returns in Bitcoin for 18 months through founder Amit Bhardwaj's mining and MLM network. Police called it one of India's biggest crypto Ponzi schemes โ estimates of the total loss range from roughly Rs 2,000 crore to figures in the billions of dollars โ and arrests and asset seizures were still happening as recently as 2024-2025, years after Bhardwaj's 2018 arrest and his 2022 death.
The Antrix-Devas Deal Case
ISRO's commercial arm signed away scarce S-band spectrum to a little-known start-up, then annulled the deal on national-security grounds after a political storm โ triggering an international arbitration award of over $560 million against India. A decade later, Indian courts found the underlying deal itself was procured by fraud, wound up Devas, and set the arbitration award aside, even as foreign courts have moved to enforce it anyway.