ADVERTISEMENT
  • Home
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Thursday, June 18, 2026
  • Login
Vegas Valley News
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Technology
  • Entertainment
  • Travel
  • Lifestyle
  • Vegas Valley News asks for your consent to use your personal data to:
  • VVN Opt out of the sale or sharing of personal information
No Result
View All Result
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Technology
  • Entertainment
  • Travel
  • Lifestyle
  • Vegas Valley News asks for your consent to use your personal data to:
  • VVN Opt out of the sale or sharing of personal information
No Result
View All Result
Vegas Valley News
No Result
View All Result
Home Technology

Frontier Airways is leaking your passport and bank card particulars from a boarding cross

by Vegas Valley News
June 18, 2026
in Technology
0
Frontier Airways is leaking your passport and bank card particulars from a boarding cross
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter


A scorching potato: A safety researcher has found critical vulnerabilities in Frontier Airways’ reserving system. Utilizing simply two items of knowledge printed on each boarding cross – a reserving code and a final identify – anybody can pull full passport numbers, residence addresses, TSA PreCheck codes, and practically full bank card particulars from the airline’s API. The vulnerabilities have been recognized for over three months.

If you happen to’ve ever flown Frontier Airways and your boarding cross ended up in a photograph, a trash can, or a social media submit, your private information could also be accessible to anybody proper now.

A safety researcher going by BobDaHacker revealed an in depth disclosure this week revealing that Frontier’s cell API and reserving administration pages expose the complete private information of each passenger on a reservation to anybody armed with a reserving code and a final identify.

Each are printed on each boarding cross, and each are encoded within the barcode. The researcher first reported the problems to Frontier on March 3. It’s now June 18, 105 days later, and the important vulnerabilities stay dwell.

The assault is easy. Frontier’s cell API endpoint accepts a six-character PNR (Passenger Identify Report) and a final identify, and returns a full inner reserving object that features, for each passenger on the reservation:

  • Full residence deal with (road, metropolis, state, ZIP)
  • Electronic mail deal with and telephone quantity
  • Full date of start, together with for minors
  • Full, unmasked passport quantity, issuing nation, and expiration date
  • Recognized Traveler Quantity (TSA PreCheck identifier)
  • Frontier Miles loyalty quantity
  • Bank card BIN (first 6 digits), final 4 digits, expiration date, cardholder identify, and full billing deal with
  • Fee historical past with authorization codes
  • The bank card math

The cost publicity is extra critical than it sounds. BobDaHacker explains that the BIN (the primary six digits of a card quantity) mixed with the final 4 digits already seen leaves solely 5 digits unknown. The sixteenth digit is a deterministic Luhn test digit, calculable from the opposite 15. Meaning roughly 100,000 doable mixtures for the remaining center digits – trivially iterable in a script.

With the cardholder’s identify, expiration date, and full billing deal with (which satisfies AVS verification for card-not-present transactions) additionally uncovered, the CVV turns into the only real remaining safety management.

Past the cell API, BobDaHacker discovered that Frontier’s web site leaks information via its personal “Handle My Reserving” pages. The Passengers/Edit web page, reachable with the identical PNR and final identify, shows full passport numbers, dates of start, and KTNs, and likewise embeds them in a server-rendered JSON blob within the web page supply.

When Frontier tried to repair an earlier electronic mail leak on the Handle My Reserving web page, it launched two new leaks – considered one of which additionally uncovered telephone numbers.

There was additionally a fourth vulnerability: an endpoint that returned reserving information from a PNR alone, with no final identify required. That one Frontier did repair. The corporate additionally despatched the researcher a mannequin airplane. The remaining stays unpatched.

A former Frontier worker who reached out after BobDaHacker’s submit went dwell provided some context for why the codebase could be on this state. “IBE was already thought of a legacy codebase,” he wrote, referring to the reserving system seen within the researcher’s screenshots. “We have been speaking about sunsetting it and changing it with a cleaner, extra trendy resolution. IBE was a multitude of generated config and code that just one individual was senior sufficient to the touch. Everybody else principally danced round it.” The worker added that the safety incident got here as no shock given the office tradition they’d skilled.

BobDaHacker adopted customary accountable disclosure all through, with an preliminary report on March 3, a number of follow-ups, and a proper 30-day deadline set for June 12 that Frontier let cross with out response. As of writing, Frontier has not issued a public assertion.

Tags: AirlinesBoardingCardCreditDetailsFrontierleakingPasspassport
Vegas Valley News

Vegas Valley News

Vegas Valley News Local, Breaking News

Next Post
When the World Cup Involves City, the Complete Metropolis Turns into the Stadium 

When the World Cup Involves City, the Complete Metropolis Turns into the Stadium 

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Peppermint Date Bark Recipe

Peppermint Date Bark Recipe

7 months ago
My Pure Spring Cleansing Guidelines (Room by Room)

My Pure Spring Cleansing Guidelines (Room by Room)

3 months ago

Popular News

  • ‘Flesh-Consuming’ Micro organism Circumstances Rising on Gulf Coast: What to Know

    ‘Flesh-Consuming’ Micro organism Circumstances Rising on Gulf Coast: What to Know

    0 shares
    Share 0 Tweet 0
  • FIFA Fever is Taking Over South Florida

    0 shares
    Share 0 Tweet 0
  • James Gunn Nonetheless ‘Working On’ Viola Davis-Led Amanda Waller Sequence

    0 shares
    Share 0 Tweet 0
  • April Taste Information | Life-style Media Group

    0 shares
    Share 0 Tweet 0
  • ‘John Sweet: I Like Me’ trailer — Canadian actor’s life explored in documentary

    0 shares
    Share 0 Tweet 0

About Us

Vegas Valley News, based in Las Vegas, Nevada, is your go-to source for local news and events. Stay updated with the latest happenings in our vibrant community. For advertising opportunities, contact us at sales@vegasvalleynews.com. Your connection to the pulse of Vegas!

Category

  • Business
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • World

Recent Posts

  • When the World Cup Involves City, the Complete Metropolis Turns into the Stadium 
  • Frontier Airways is leaking your passport and bank card particulars from a boarding cross
  • Israel severs contact with EU’s Kallas over reported apartheid remarks — RT World Information
  • Home
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2024 Vegasvalleynews.com | All Rights Reserved.

No Result
View All Result
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Technology
  • Entertainment
  • Travel
  • Lifestyle
  • Vegas Valley News asks for your consent to use your personal data to:
  • VVN Opt out of the sale or sharing of personal information

Copyright © 2024 Vegasvalleynews.com | All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Verified by MonsterInsights