FlightAware configuration error exposed account data for over three years
- Organization
- FlightAware
- Exploit
- Misconfiguration
- Industry
- Aviation Technology
FlightAware, the flight tracking service owned by Collins Aerospace, notified users in August 2024 that a configuration error had left account information accessible. The company said it discovered the problem on July 25, 2024 and corrected it, then emailed affected customers on August 17.
The exposure window ran back to January 1, 2021, meaning account data had been reachable for more than three years. FlightAware said the error may have exposed user IDs, passwords and email addresses and, depending on what a customer had entered, full names, billing and shipping addresses, IP addresses, social media account details, phone numbers, year of birth, the last four digits of a credit card, aircraft owned, job title, pilot status and account activity records.
Social Security numbers were also implicated, though narrowly. According to Simple Flying, 16 such numbers were potentially exposed because users had typed digits formatted as Social Security numbers into free-form fields not intended to hold them.
FlightAware required users to reset their passwords at their next login and offered two years of complimentary credit monitoring. Matt Davis of FlightAware said the company had addressed the configuration error, but the company did not say whether anyone had actually accessed the exposed records and did not publish a total number of affected accounts. The service reports roughly 13 million users and more than 10,000 aircraft operators.