Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Tesla Readies a Taxi Service in San Francisco—but Not With Robotaxis

26 July 2025

Samsung Galaxy S25 FE Colours, RAM and Storage Configurations Tipped

25 July 2025

Frostpunk 2 Arrives On Consoles In September

25 July 2025
Facebook X (Twitter) Instagram
Just In
  • Tesla Readies a Taxi Service in San Francisco—but Not With Robotaxis
  • Samsung Galaxy S25 FE Colours, RAM and Storage Configurations Tipped
  • Frostpunk 2 Arrives On Consoles In September
  • Apple Rolls Out Additional iOS 26 Beta 4 Build Alongside First Public Beta
  • Wolfenstein TV Series Reportedly In Development At Amazon
  • Join Our Next Livestream: Inside Katie Drummond’s Viral Interview With Bryan Johnson
  • Samsung’s Exynos 2600 SoC Listed on Geekbench; Could Power the Galaxy S26 Series
  • Dying Light: The Beast Delayed One Month
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » A Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats
News

A Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

News RoomBy News Room24 July 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

An airline leaving all of its passengers’ travel records vulnerable to hackers would make an attractive target for espionage. Less obvious, but perhaps even more useful for those spies, would be access to a premium travel service that spans 10 different airlines, left its own detailed flight information accessible to data thieves, and seems to be favored by international diplomats.

That’s what one team of cybersecurity researchers found in the form of Airportr, a UK-based luggage service that partners with airlines to let its largely UK- and Europe-based users pay to have their bags picked up, checked, and delivered to their destination. Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US.

“Anyone would have been able to gain or might have gained absolute super-admin access to all the operations and data of this company,” says Himanshu Pathak, CyberX9’s founder and CEO. “The vulnerabilities resulted in complete confidential private information exposure of all airline customers in all countries who used the service of this company, including full control over all the bookings and baggage. Because once you are the super-admin of their most sensitive systems, you have have the ability to do anything.”

Airportr’s CEO Randel Darby confirmed CyberX9’s findings in a written statement provided to WIRED but noted that Airportr had fixed the vulnerabilities a few days after the researchers made the company aware of the issues last April. “The data was accessed solely by the ethical hackers for the purpose of recommending improvements to Airportr’s security, and our prompt response and mitigation ensured no further risk,” Darby wrote in a statement. “We take our responsibilities to protect customer data very seriously.”

CyberX9’s researchers, for their part, counter that the simplicity of the vulnerabilities they found mean that there’s no guarantee other hackers didn’t access Airportr’s data first. They found that a relatively basic web vulnerability allowed them to change the password of any user to gain access to their account if they had just the user’s email address—and they were also able to brute-force guess email addresses with no rate limitations on the site. As a result, they could access data including all customers’ names, phone numbers, home addresses, detailed travel plans and history, airline tickets, boarding passes and flight details, passport images, and signatures.

By gaining access to an administrator account, CyberX9’s researchers say, a hacker could also have used the vulnerabilities it found to redirect luggage, steal luggage, or even cancel flights on airline websites by using Airportr’s data to gain access to customer accounts on those sites. The researchers say they could also have used their access to send emails and text messages as Airportr, a potential phishing risk. Airportr tells WIRED that it has 92,000 users and claims on its website that it has handled more than 800,000 bags for customers.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleiQOO Z10R 5G With MediaTek Dimensity 7400 SoC, 5,700mAh Battery Launched in India: Price, Specifications
Next Article Donkey Kong Bananza Review – Breaking Through To Something New

Related Articles

News

Tesla Readies a Taxi Service in San Francisco—but Not With Robotaxis

26 July 2025
News

Join Our Next Livestream: Inside Katie Drummond’s Viral Interview With Bryan Johnson

25 July 2025
News

Trump’s Anti-Bias AI Order Is Just More Bias

25 July 2025
News

Review: AirPods Max

25 July 2025
News

Review: Somnee Smart Sleep Headband

25 July 2025
News

Review: Samsung Galaxy Watch8 and Watch8 Classic

25 July 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024103 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Oppo Reno 14, Reno 14 Pro India Launch Timeline and Colourways Leaked

27 May 202582 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

Join Our Next Livestream: Inside Katie Drummond’s Viral Interview With Bryan Johnson

News Room25 July 2025
Phones

Samsung’s Exynos 2600 SoC Listed on Geekbench; Could Power the Galaxy S26 Series

News Room25 July 2025
Gaming

Dying Light: The Beast Delayed One Month

News Room25 July 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025125 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024103 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Apple Rolls Out Additional iOS 26 Beta 4 Build Alongside First Public Beta

25 July 2025

Wolfenstein TV Series Reportedly In Development At Amazon

25 July 2025

Join Our Next Livestream: Inside Katie Drummond’s Viral Interview With Bryan Johnson

25 July 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.