August 17th, 2024

Flightaware Security Breach

FlightAware reported a security breach on July 25, 2024, exposing user personal information. Affected users must reset passwords, raising concerns about security practices and accountability for data breaches.

Read original articleLink Icon
Flightaware Security Breach

On July 25, 2024, FlightAware reported a security breach due to a configuration error that may have exposed personal information of its users. The compromised data potentially included user IDs, passwords, email addresses, full names, billing and shipping addresses, IP addresses, social media accounts, phone numbers, birth years, last four digits of credit card numbers, and details about aircraft ownership and pilot status. FlightAware has expressed regret over the incident and has taken immediate action to rectify the error. They are requiring all affected users to reset their passwords as a precautionary measure. The breach has raised concerns among users regarding the security of their passwords and the adequacy of encryption practices employed by the company. Discussions among users in forums reflect a mix of frustration and suggestions for stricter penalties for companies that experience data breaches.

- FlightAware experienced a security breach exposing user personal information.

- Affected data may include passwords, email addresses, and billing information.

- FlightAware has mandated password resets for potentially impacted users.

- Users expressed concerns about password security and encryption practices.

- The incident has sparked discussions on accountability for data breaches.

Link Icon 3 comments
By @amatecha - 5 months
The full text of the email sent to users was posted here: https://discussions.flightaware.com/t/closing-account-due-th...

I'm especially curious what this is intended to mean: "Please note that this notification was not delayed as a result of a law enforcement investigation."

The notification was not delayed? Or was? o_O