logo

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. (Corrected)

ID: 8b3b32ff-fcde-52c0-ad50-aa5de8a07928

STIX ID: report--8b3b32ff-fcde-52c0-ad50-aa5de8a07928

Feed Name: DataBreaches.Net

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-30

Author: Dissent

...
...

Frontier Airlines faced multiple security failures this year: a researcher (BobDaHacker) disclosed API and client‑side vulnerabilities that exposed full booking objects (accessible with only a PNR + last name) and plaintext Known Traveler Numbers in rendered JavaScript; a separate confirmed breach (May–June) allegedly exfiltrated employee and passenger PII including SSNs, passport numbers, KTNs, and payment/driver’s license data with notifications sent in July; and a dark‑web group (ExfilSquad) later claimed a ~43 GB/2.4M‑record dump from Microsoft Power Apps/Dynamics 365 misconfigurations, giving Frontier until Aug 5 to respond.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.