Skip to main content

A flaw in e-ticket systems could mean a hacker can print your boarding pass

best flight tracking apps
Trevor Mogg / Trevor Mogg

Security researchers at the firm Wandera have exposed a vulnerability in the e-ticking system used by several popular global airlines. The vulnerability was discovered in December and involves unsecured check-in emails that can put the personal information of passengers at risk or even allow a hacker to print boarding passes.

Though there is no evidence that currently supports a major data breach, eight airlines including Southwest, Air France, KLM, Vueling, Jetstar, Thomas Cook, Transavia, and Air Europa are impacted by this vulnerability. According to Wandera, these airliners are sending unencrypted check-in links, which otherwise automatically log passengers into a website to check flight status and print boarding passes. That can allow a hacker who is sharing the same Wi-Fi network as a passenger to intercept the link and gain access to the same information.

Recommended Videos

Several types of personally identifiable information can be accessed through this vulnerability, including passport information, seat assignments, first and last names and baggage selections. However, the type of information that can be stolen depends on each airline e-ticking system. In some cases, hackers can still leverage this information to their advantage to change an itinerary. That includes the ability to add or remove extra bags, change seating arrangements, or alter both the mobile phone number or email associated with a booking.

Please enable Javascript to view this content

“Our threat research team observed that travel-related passenger details were being sent without encryption as one of our secured customers accessed the e-ticketing system of one of the airlines mentioned above. It was at that time that Wandera notified the airline and began further research,” Wandera said.

The vulnerability was shared the appropriate government agencies as well as with the airlines. A period of four weeks is given for the vulnerability to be fixed before it was made public. As a solution, Wandera recommends for airlines to adopt strong encryption methods, require user authentication, and use one-time tokens for links in emails.

This would not be the first time that airliners have faced scrutiny relating to its cybersecurity practices. Though more severe, a British Airways data hack in 2018 impacted more than 380,000 passengers after its computer systems were breached. A separate instance with Cathay Pacific also impacted up to 10 million of its customers in 2018.

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
20 years on, the Mac mini is in the best shape of its life
The Mac mini up on its side on a desk.

The original Mac mini was released 20 years ago today. And while it was a miniature marvel when it debuted, it’s gone from strength to strength in the years since. Today, it’s one of the best desktop computers you can buy.

When Steve Jobs pulled out the first Mac mini on stage in 2005, it was met with gasps and cheers from the audience, such was its unbelievably compact form factor. Yet when it was introduced, Jobs’ description of it was somewhat underwhelming: “This is a very robust computer, but it’s very, very tiny.” You got the feeling that even Apple wasn’t taking it particularly seriously.

Read more
AMD calls Intel’s Arrow Lake ‘horrible’
Fingers holding an Intel 285K.

Shots fired. Frank Azor, an AMD executive, just straight-up called Intel's Arrow Lake line of CPUs "horrible." Where did it all start? Why, with the ongoing shortage of AMD’s best gaming processors, of course. And surprisingly, AMD blames Intel for the fact that its X3D processors are hard to come by right now.

In a recent media roundtable reported by Tom's Hardware, AMD admitted that it never expected the demand for its CPUs to be that high. In fact, it expected it to be lower because it thought that Intel would be more competitive -- but since Arrow Lake turned out to be largely unimpressive, people turned to AMD for their next-gen CPUs even more so than before.

Read more
Lenovo Legion Go S vs. Steam Deck OLED: here’s what we know so far
The Lenovo Legion Go S with SteamOS installed.

 

Lenovo's Legion Go 2 was one of the worst-kept secrets for CES 2025, but now we don't need to pretend anymore, as we've not only seen it in the flesh, but we've had some hands-on time with it too, and we're very excited. With an upgraded display, processor, and newly affordable price tag, the Legion Go S is gunning for the Steam Deck's crown. Most importantly, it'll likely be the first dedicated SteamOS handheld available outside of the Steam Deck -- although SteamOS will be more widely available in general too.

Read more