August 19th, 2024

FlightAware configuration error leaked user data for years

FlightAware reported a data security incident exposing user information for over three years due to a configuration error. Affected users must reset passwords and are offered 24 months of identity protection.

Read original articleLink Icon
FlightAware configuration error leaked user data for years

FlightAware, a major flight tracking platform, has reported a data security incident that may have exposed user information due to a configuration error. The issue, which occurred on January 1, 2021, was discovered on July 25, 2024, leaving personal data vulnerable for over three years. Affected users are being prompted to reset their passwords upon their next login. The exposed data may include user IDs, passwords, email addresses, full names, billing and shipping addresses, IP addresses, social media accounts, telephone numbers, birth years, last four digits of credit card numbers, aircraft ownership details, pilot status, industry titles, account activity, and Social Security numbers. FlightAware has since corrected the configuration error and is offering a 24-month identity protection package through Equifax to those impacted. Users are advised to monitor their accounts for suspicious activity and to change passwords on other platforms if they used the same credentials. The company has been contacted for further details regarding unauthorized access and the number of users affected.

- FlightAware's configuration error exposed user data for over three years.

- Users are required to reset their passwords due to the breach.

- Exposed data may include sensitive information such as Social Security numbers and credit card details.

- Affected users are offered a free identity protection package for 24 months.

- Users should change passwords on other platforms if the same credentials were used.

Link Icon 1 comments