Close Menu
Entertainment Industry Reporter
    Facebook X (Twitter) Instagram
    Entertainment Industry Reporter
    • Home
    • Film
    • Television
    • Box Office
    • Reality TV
    • Music
    • Horror
    • Politics
    • Books
    • Technology
    • Popular Music Videos
    • Cover Story
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyright Disclaimer
      • Privacy Policy
      • Terms and Conditions
    Entertainment Industry Reporter
    You are at:Home»Technology»A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats
    Technology

    A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

    By AdminJuly 24, 2025
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats


    An airline leaving all of its passengers’ travel records vulnerable to hackers would make an attractive target for espionage. Less obvious, but perhaps even more useful for those spies, would be access to a premium travel service that spans 10 different airlines, left its own detailed flight information accessible to data thieves, and seems to be favored by international diplomats.

    That’s what one team of cybersecurity researchers found in the form of Airportr, a UK-based luggage service that partners with airlines to let its largely UK- and Europe-based users pay to have their bags picked up, checked, and delivered to their destination. Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED, they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US.

    “Anyone would have been able to gain or might have gained absolute super-admin access to all the operations and data of this company,” says Himanshu Pathak, CyberX9’s founder and CEO. “The vulnerabilities resulted in complete confidential private information exposure of all airline customers in all countries who used the service of this company, including full control over all the bookings and baggage. Because once you are the super-admin of their most sensitive systems, you have have the ability to do anything.”

    Airportr’s CEO Randel Darby confirmed CyberX9’s findings in a written statement provided to WIRED but noted that Airportr had fixed the vulnerabilities a few days after the researchers made the company aware of the issues last April. “The data was accessed solely by the ethical hackers for the purpose of recommending improvements to Airportr’s security, and our prompt response and mitigation ensured no further risk,” Darby wrote in a statement. “We take our responsibilities to protect customer data very seriously.”

    CyberX9’s researchers, for their part, counter that the simplicity of the vulnerabilities they found mean that there’s no guarantee other hackers didn’t access Airportr’s data first. They found that a relatively basic web vulnerability allowed them to change the password of any user to gain access to their account if they had just the user’s email address—and they were also able to brute-force guess email addresses with no rate limitations on the site. As a result, they could access data including all customers’ names, phone numbers, home addresses, detailed travel plans and history, airline tickets, boarding passes and flight details, passport images, and signatures.

    By gaining access to an administrator account, CyberX9’s researchers say, a hacker could also have used the vulnerabilities it found to redirect luggage, steal luggage, or even cancel flights on airline websites by using Airportr’s data to gain access to customer accounts on those sites. The researchers say they could also have used their access to send emails and text messages as Airportr, a potential phishing risk. Airportr tells WIRED that it has 92,000 users, and claims on its website that it’s handled over 800,000 bags for customers.



    Original Source Link

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    Related Posts

    OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further

    This Jammer Wants to Block Always-Listening AI Wearables. It Probably Won’t Work

    Netflix’s version of Overcooked lets you play as Huntr/x

    Sleep Apnea Often Goes Undetected in Women. That’s Starting to Change

    Amazon.com is experiencing issues and failing to load prices

    These $500 Windows Laptops Show the MacBook Neo’s Competition

    Popular Posts

    ‘Maybe Happy Ending’, ‘Death Becomes Her’ See Promising Broadway Numbers

    ‘Watchmen,’ ‘Boyz n the Hood’ & More Regina King Hits We Can’t Stop Watching

    Withings BPM Vision Review: At-Home Blood Pressure Monitoring

    ‘Twisters’ Begins With $7M In Previews

    Survivor 47, Episode 8 Recap: He’s All That

    ‘Jeopardy!’ Fans React to Priest’s Narrow Win & Players’ ‘Groan’-Inducing Fail

    Fortnite’s Fortnitemares Event to Add Jack Skellington and Michael Myers to the Game

    Categories
    • Books (1,964)
    • Box Office (1,380)
    • Cover Story (33)
    • Events (23)
    • Featured (39)
    • Film (1,982)
    • Horror (1,969)
    • Lifestyle (9)
    • Music (2,047)
    • Politics (1,111)
    • Popular Music Videos (1,402)
    • Reality TV (1,426)
    • Technology (1,976)
    • Television (1,744)
    • Uncategorized (1)
    Archives
    Useful Links
    • About
    • Contact
    • Privacy Policy
    • DMCA / Copyright Disclaimer
    • Amazon Disclaimer
    • Terms and Conditions
    Categories
    • Books (1,964)
    • Box Office (1,380)
    • Cover Story (33)
    • Events (23)
    • Featured (39)
    • Film (1,982)
    • Horror (1,969)
    • Lifestyle (9)
    • Music (2,047)
    • Politics (1,111)
    • Popular Music Videos (1,402)
    • Reality TV (1,426)
    • Technology (1,976)
    • Television (1,744)
    • Uncategorized (1)
    Popular Posts

    8 Best Disney Halloween Episodes to Get You in the Spooky Spirit

    Imagine Dragons, J Balvin Together For ‘Eyes Closed’

    Broadway Box Office Stumbles During July 4th Holiday Week

    Dance Radio Hits 2023 – Dance Music 2024 – Top Hits 2023 Pop Music 2024′ New English Songs 2023 Best

    © 2026 Entertainment Industry Reporter. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT