A Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

Security Flaws in Luggage Service Expose Sensitive User Data, Including Diplomatic Travel Details
Photo: WIRED

Security Flaws in Luggage Service Expose Sensitive User Data, Including Diplomatic Travel Details

A UK-based luggage service, Airportr, which partners with multiple major airlines, faced severe security vulnerabilities that exposed the personal information and travel plans of its users, including government officials and diplomats. Researchers from CyberX9 discovered these flaws, which allowed them to access user data, change account passwords, and even potentially steal or redirect luggage. The vulnerabilities were tied to basic web bugs that granted access to sensitive data such as passport images, boarding passes, and flight details. In some cases, attackers could impersonate the company, sending phishing messages to users. The researchers also found diplomatic passport data in the exposed records, with details of travelers from the UK, US, and Switzerland. Airportr confirmed the breach but responded swiftly by fixing the vulnerabilities. While the company claims no further risks emerged, cybersecurity experts argue that smaller third-party services like Airportr pose significant security risks, especially when connected to large travel networks. The airlines involved were not informed about the breach until after researchers made the issue public. This incident highlights the need for enhanced security measures for third-party services that handle sensitive data.

Leave a Reply

Your email address will not be published. Required fields are marked *