Air France-KLM appears in reporting on third-party breaches affecting customer data, in the same campaign as the Qantas file at 26-0702.
Two Distinct Aviation Exposures, Both Filed This Year
This desk has now covered aviation twice through different mechanisms. The April disruption at 26-0406 was operational: shared passenger-processing software failing across several hubs at once.
This is the other kind — customer data reached through a third-party platform, with no operational consequence at all. The airline flew normally throughout.
They are unrelated technically and share a root cause: airlines buy heavily from a small supplier base, so both their operations and their customer records sit substantially in other people’s systems.
Frequent-Flyer Records Are The Durable Asset
A carrier’s customer database is a travel history with an identity attached, and for many passengers it includes the passport details required to fly, as filed at 26-0527.
Loyalty balances also have direct value — points are transferable, redeemable and frequently protected by nothing stronger than a member number and a surname.
Graded medium. The third-party route is reported consistently; scope and affected counts are not established.
Compiled from public reporting, listed below. Scope has not been disclosed and we are not estimating it. Corrections: corrections@forensicpost.com.