Adventure's Sky Ticket site accessed, up to 29,780 records affected

On 9 October Adventure announced that its Sky Ticket reservation site had been accessed by a third party, potentially leaking user personal data.
The breach involved three types of unauthorized access: server access; business management system access on 20 September, discovered on 28 September, affecting 17,780 records with names, phone numbers and refund account details; and bus reservation service data viewing from 3 August to 1 October, discovered on 1 October, affecting about 12,000 reservations with personal and payment details. No credit card numbers or passport images were stored or leaked.
Adventure has blocked the access route, applied vulnerability fixes, disabled stored card payments, reported the incident to the Personal Information Protection Commission and urged users to change passwords and review reservation history and card statements.