Nearly 450 islanders' data could have been breached in a hack on LibertyBus and CTPlus Guernsey's websites.
The Channel Islands bus operators fell victim to a phishing attack.
It intercepted the link between the main websites and top-up pages for the Avanchicard and Puffinpass.
A duplicate log-in page was created at some point after 29th April, asking users to fill in their email address or pass number and password.
It was shut down within hours of being discovered on 15th May.
LibertyBus says there is a 'limited risk of fraudulent activity',
"No credit/debit card details were accessed and at no point was the central databasen of Avanchicard holders compromised."
Emails have been sent to the 361 people in Jersey and 82 people in Guernsey possibly affected telling them their passwords have been automatically reset.
Investigations into how the attack happened are underway, and the Information Commissioner has been informed.
"LibertyBus is now working closely with the regulatory authorities and their suppliers to investigate how this incident occurred. They are also working hard to put measures in place to ensure that an incident of this nature does not happen again."
Any customers who are concerned should contact info@libertybus.je
The top-up section of the LibertyBus website will be unavailable at times in the coming weeks for testing and investigations. Customers are being asked to top-up at the Customer Services desk at Liberation Station.

St Saviour break and entry suspect pictured posing on motorbike
'Overstretched' neurology department following under-experienced managers
Channel Islanders asked to report injured or dead seabirds
'Concerning' e-bike rider not stopping for police
Scottish man (27) jailed for smuggling £17,500 worth of cocaine to Jersey
'Jersey Lifts' drivers could be fined £10,000
Railway Walk still closed and 'extremely unsafe'
3 in 4 Jersey cats not microchipped or registered incorrectly
Comments
Add a comment