The airline Swiss International Air Lines has closed a security gap through which sensitive personnel data from Pilot assessments were accessed without authorization for a period of approximately two months. An internal error in the permission settings of the data storage system caused the data leak, which affected application documents, test results, and reports. The company was alerted to the incident by an employee on August 1st and immediately blocked access.
According to Swiss, around 70 attempts to access the data were recorded. Those affected included former pilot applicants and external individuals for whom Swiss had conducted assessments on behalf of partner companies. The airline emphasized that no passenger data or data of other employees were compromised. The company described the incident as a human error by an employee and apologized for it. It clarified that it was not a hacker attack.
Following the discovery of the data breach, Swiss moved the affected data to a different, secure platform, encrypted it, and implemented additional security measures. The individuals who accessed the data were contacted and asked to delete it. The relevant data protection authorities and partner organizations were also promptly informed.
Swiss has thoroughly analyzed the incident and is developing concrete measures to prevent similar errors in the future. The company has assured that it is reviewing and strengthening its processes for protecting sensitive data. Data breaches, which occur repeatedly at other companies, are often due to human error or faulty configurations in complex systems. The Swiss case demonstrates the importance of regular reviews of access authorizations to ensure the confidentiality of personnel information.