Your Personal Data Was Potentially Exposed by a Flaw in 140+ Airlines' Software
Most travelers know not to share un-masked photos their boarding passes online. By scanning the barcode or just reading the name and reservation number off the boarding pass, anyone can access your personal data and may be able to change or cancel your flight. However, until last week, hackers didn't need your boarding pass to get your data or wreak havoc on your reservation if it was booked through one of more than 140 airlines.
While the average flyer probably has not heard of Amadeus or Sabre, most airlines across the world use one of these two major reservation systems. And Israeli hacker Noam Rotem -- working with Safety Detective -- discovered a major flaw in Amadeus that left a backdoor open for hackers to easily access passengers' data, including birthday, address, email, phone number and access to frequent flyer accounts.
Chances are you've booked a flight through one of the airlines that uses the Amadeus reservation system. These airlines include: Air Canada, Air France, ANA, Asiana, Austrian, British Airways, Brussels Airlines, Cathay Pacific, El Al, EVA Airways, Finnair, Iberia, Icelandair, KLM, Korean Airways, Lufthansa, Malaysian Airlines, OpenSkies, Qantas, SAS, Singapore Airlines, SWISS, TAP Portugal, Thai Airways and many more.

Even without this flaw, it doesn't take much to access an airline reservation. Typically, all you need is the last name of the passenger and the Personal Name Record (PNR) for the reservation. However, using El Al's reservation system, researchers found that they could simply tweak a URL to pull up any Amadeus reservation using just the six-digit Personal Name Record (PNR). The passenger's last name wasn't required.
Even worse, the researchers found that there was no limitation in place to keep them from randomly generating numbers and pinging the Amadeus system to check if there was an active reservation using that PNR. While there are around two million possible six-digit alphanumeric combinations, the researchers were able to go through possibilities with decent speed:
Through this process they were able to retrieve an undisclosed number of active reservations. And once they found a match, the researchers report:
"We were able to log into El Al's customer portal and make changes, claim frequent flyer miles to a personal account, assign seats and meals, and update the customer's email and phone number, which could then be used to cancel/change flight reservation via customer service."
Being "white-hat hackers," the researches shared their discovery with Amadeus -- along with suggestions to add reservation passwords, captcha and other "bot protection mechanisms" to keep this from being possible in the future.
Amadeus responded to Safety Detective that it "took immediate action" to fix the issue and "can now confirm that the issue is solved."
"To further strengthen security, we have added a Recovery PTR to prevent a malicious user from accessing travelers' personal information, the company's statement continued. "We regret any inconvenience this situation might have caused."
As this wasn't a traditional hack -- like Marriott, Cathay Pacific, Equifax and more -- its unclear how many passengers' data may have been exposed through this simple reservation access method. Amadeus says it hasn't detected a data breach.
"We became alerted to an issue in one of our products and our technical teams took immediate action and as of January 16 the issue was fixed," Amadeus said in a statement to TPG. "We can confirm that Amadeus has not detected any data breach and that no data from travelers was disclosed. We regret any disruption this situation may have caused."
However, it seems it would be tough for Amadeus to be sure that "no data from travelers was disclosed." It's possible that Amadeus could see from its logs whether another brute-force attack -- similar to the one that the researchers used -- had been employed. However, this reservation access method is identical to how El Al passengers would access their reservations when clicking through a confirmation email. Indeed, that's how the hacker discovered this access method. So, at the very least, it would likely be difficult to say for sure that bad actors didn't utilize this reservation access method on a smaller scale.
Looking forward, there clearly needs to be a better way to secure flight reservation data than the archaic procedure that simply requires a PNR and the traveler's last name. In its statement, Amadeus emphasizes that it realizes this and is working "together with our customers and partners in the industry to address PNR security overall."
"The airline industry relies on IATA standards that were introduced to improve efficiency and customer service on a global scale," the company said. "Because the industry works on common industry standards, including the PNR, further improvements should include reviewing and changing some of the industry standards themselves, which will require industry collaboration."
Speaking of the International Air Transportation Association (IATA), the standard-setting industry group finally released a statement on Wednesday -- almost a week after the disclosure about the backdoor. The statement pledges that "IATA is committed to working with industry stakeholders to ensure passenger information remains secure."
The Department of Transportation and Federal Aviation Administration were unable to be reached for comment due to the partial government shutdown.
TPG featured card
Rewards
| 2X miles | 2 miles per dollar on every purchase |
| 5X miles | 5 miles per dollar on flights and vacation rentals booked through Capital One Business Travel |
| 10X miles | 10 miles per dollar on hotels and rental cars booked through Capital One Business Travel |
Intro offer
Annual Fee
Recommended Credit
Why We Chose It
The Capital One Venture X Business Card has all the Capital One Venture X Rewards Credit Card has to offer and more. It offers an incredible welcome bonus and requires an equally impressive spend to qualify. In addition, the card comes with premium travel perks like annual travel credit. (Partner offer)Pros
- The Capital One Venture X business card has a very lucrative welcome offer.
- In addition, the card comes with many premium travel perks such as an annual $300 credit for bookings through Capital One Business Travel.
- Business owners are also able to add employee cards for free.
Cons
- The card requires significant spending to earn the welcome offer.
- Another drawback is that the annual travel credit can only be used on bookings made through Capital One Business Travel.
- LIMITED-TIME OFFER: Earn up to 400K bonus miles: 200K miles when you spend $30K in the first 3 months, and an additional 200k miles when you spend $150k in the first 6 months
- Earn unlimited 2X miles on every purchase, everywhere—with no limits or category restrictions
- Earn 10X miles on hotels and rental cars and 5X miles on flights and vacation rentals booked through Capital One Business Travel
- With no preset spending limit, enjoy big purchasing power that adapts so you can spend more and earn more rewards
- Empower your teams to make business purchases while earning rewards on their transactions, with free employee and virtual cards. Plus, automatically sync your transaction data with your accounting software and pay your vendors with ease
- Redeem your miles on flights, hotels and more. Plus, transfer your miles to any of the 15+ travel loyalty programs
- Every year, you'll get 10,000 bonus miles after your account anniversary date. Plus, receive an annual $300 credit for bookings made through Capital One Business Travel
- Receive up to a $120 credit for Global Entry or TSA PreCheck®. Enjoy access to 1,300+ airport lounges worldwide, including Capital One Lounge locations and Priority Pass™ lounges, after enrollment
- Enjoy a $100 experience credit and other premium benefits with every hotel and vacation rental booked from the Premier Collection
- This is a pay-in-full card, so your balance is due in full every month
Rewards Rate
| 2X miles | 2 miles per dollar on every purchase |
| 5X miles | 5 miles per dollar on flights and vacation rentals booked through Capital One Business Travel |
| 10X miles | 10 miles per dollar on hotels and rental cars booked through Capital One Business Travel |
Intro Offer
Earn 200K miles when you spend $30K in the first 3 months, and an additional 200K miles when you spend $150K in the first 6 monthsLIMITED-TIME OFFER: Earn up to 400K bonus milesAnnual Fee
$395Recommended Credit
Credit ranges are a variation of FICO® Score 8, one of many types of credit scores lenders may use when considering your credit card application.740-850Excellent
Why We Chose It
The Capital One Venture X Business Card has all the Capital One Venture X Rewards Credit Card has to offer and more. It offers an incredible welcome bonus and requires an equally impressive spend to qualify. In addition, the card comes with premium travel perks like annual travel credit. (Partner offer)Pros
- The Capital One Venture X business card has a very lucrative welcome offer.
- In addition, the card comes with many premium travel perks such as an annual $300 credit for bookings through Capital One Business Travel.
- Business owners are also able to add employee cards for free.
Cons
- The card requires significant spending to earn the welcome offer.
- Another drawback is that the annual travel credit can only be used on bookings made through Capital One Business Travel.
- LIMITED-TIME OFFER: Earn up to 400K bonus miles: 200K miles when you spend $30K in the first 3 months, and an additional 200k miles when you spend $150k in the first 6 months
- Earn unlimited 2X miles on every purchase, everywhere—with no limits or category restrictions
- Earn 10X miles on hotels and rental cars and 5X miles on flights and vacation rentals booked through Capital One Business Travel
- With no preset spending limit, enjoy big purchasing power that adapts so you can spend more and earn more rewards
- Empower your teams to make business purchases while earning rewards on their transactions, with free employee and virtual cards. Plus, automatically sync your transaction data with your accounting software and pay your vendors with ease
- Redeem your miles on flights, hotels and more. Plus, transfer your miles to any of the 15+ travel loyalty programs
- Every year, you'll get 10,000 bonus miles after your account anniversary date. Plus, receive an annual $300 credit for bookings made through Capital One Business Travel
- Receive up to a $120 credit for Global Entry or TSA PreCheck®. Enjoy access to 1,300+ airport lounges worldwide, including Capital One Lounge locations and Priority Pass™ lounges, after enrollment
- Enjoy a $100 experience credit and other premium benefits with every hotel and vacation rental booked from the Premier Collection
- This is a pay-in-full card, so your balance is due in full every month

