logo

Plane tracker FlightAware admits user passwords, SSNs exposed for years

ID: 1f456d2c-0001-56aa-8897-bf73b9a88aa4

STIX ID: report--1f456d2c-0001-56aa-8897-bf73b9a88aa4

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2024-08-20

Date Updated: 2026-04-26

Author: Connor Jones

...
...

FlightAware disclosed a prolonged configuration error that potentially exposed user personal information — including user IDs, emails, names, addresses, IPs, phone numbers, account activity, last four credit-card digits, and other PII — from January 1, 2021 until discovery on July 25, 2024; the company fixed the issue, required password resets, offered two years of Equifax monitoring, and later stated only 16 SSNs were potentially exposed and that stored passwords were hashed and salted, though it did not confirm whether data was accessed by unauthorized parties.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.