Frontier Airlines Exposes Passenger Data for Over 100 Days

Frontier Airlines Exposes Passenger Data for Over 100 Days

First seen 19 Jun 2026, 15:50 UTC Cybernewsbobdahacker.com 79% similarity 66.0

Article Content

Browse articles
ThreatCluster

A significant security flaw in Frontier Airlines' booking system has exposed sensitive passenger data, including passport numbers, TSA PreCheck identifiers, and partial credit card details. The vulnerabilities have remained unaddressed for over 100 days, despite notification from ethical hacker 'bobdahacker.' Scanning the barcode on a boarding pass can reveal all this information, leaving customers vulnerable. The airline's mobile app API allows access to the complete internal booking object with just a PNR and last name. This breach affects all passengers using the airline's services, with serious implications for identity theft and fraud. Frontier Airlines has acknowledged potential IT vulnerabilities but claims they have been resolved. However, the lack of action on critical vulnerabilities raises concerns about their security posture.

Key Points: • Frontier Airlines exposed sensitive passenger data for over 100 days. • Scanning boarding pass barcodes can reveal full passport numbers and payment details. • The airline's API allows access to internal booking data with minimal authentication.

ThreatCluster AI How this analysis works

Timeline

2026-03-03
Vulnerabilities reported to Frontier Airlines
Ethical hacker 'bobdahacker' informed Frontier about critical security flaws in their booking system.
bobdahacker.com
2026-06-16
Vulnerabilities still unaddressed
Despite reporting, critical vulnerabilities remain live, with only minor issues fixed by Frontier Airlines.
bobdahacker.com
2026-06-19
Cybernews reports on data exposure
Cybernews highlights the ongoing data exposure and Frontier's response to the vulnerabilities.
Cybernews

Community

Browse all →

Tracked Entities in This Story