bobdahacker.com
Frontier Airlines Exposes Passenger Data for Over 100 Days
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A significant security flaw in Frontier Airlines' booking system has exposed sensitive passenger data, including passport numbers, TSA PreCheck identifiers, and partial credit card details. The vulnerabilities have remained unaddressed for over 100 days, despite notification from ethical hacker 'bobdahacker.' Scanning the barcode on a boarding pass can reveal all this information, leaving customers vulnerable. The airline's mobile app API allows access to the complete internal booking object with just a PNR and last name. This breach affects all passengers using the airline's services, with serious implications for identity theft and fraud. Frontier Airlines has acknowledged potential IT vulnerabilities but claims they have been resolved. However, the lack of action on critical vulnerabilities raises concerns about their security posture.
Key Points: • Frontier Airlines exposed sensitive passenger data for over 100 days. • Scanning boarding pass barcodes can reveal full passport numbers and payment details. • The airline's API allows access to internal booking data with minimal authentication.