/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CommuteAir took down a 2019 copy of the US No Fly List, after a researcher said they found it on an unsecured server and that it had 1.5M+ entries, many aliases

One of the most sensitive U.S. government documents was left online.  —  An unsecured server discovered by a security researcher …

The Daily Dot

Context & Ripple Effects

The exposure follows a 2021 discovery of a 1.9M-person terrorist watchlist on an unsecured cluster, which DHS took offline. Earlier related reports also documented an airport backup-drive misconfiguration and an exposed intelligence disk image, placing CommuteAir’s server in a recurring pattern of sensitive data copies left publicly reachable.

What distinguishes the report is that the exposed material was a 2019 copy held by an airline and included more than 1.5 million entries and aliases. It highlights the security burden created when highly sensitive government-derived lists move into operational systems outside their original custodian.

First-order effects

  • CommuteAir removed the exposed 2019 list after the researcher’s report, ending public access to that server copy.
  • People and organizations represented in the list face exposure of identifying entries and aliases from a dataset described as highly sensitive.

Second-order effects

  • The earlier DHS takedown of an unsecured watchlist makes other holders of government-derived screening data more likely to review public-facing servers and retained copies.
  • Airlines and travel-system vendors handling screening-related records face greater pressure to inventory backups and access controls, not just protect live databases.

Third-order effects

  • Repeated exposures of watchlists, airport data, and intelligence files point to a governance problem centered on proliferating copies of sensitive records across operational infrastructure.
  • If the pattern persists, security accountability will increasingly hinge on how agencies and contractors control retention and hosting of derived datasets, rather than on the original list alone.

The trend: Sensitive government and travel-security data is becoming harder to govern as operational copies and backups spread across third-party infrastructure.

Discussion

  • @mikaelthalen Mikael Thalen on x
    NEW: The federal No Fly List was exposed on an open server discovered by a security researcher last week. The list, which was being stored by the US airline CommuteAir, contained over 1.5 million rows of data including names, aliases, & birth dates. https://www.dailydot.com/...
  • @repdanbishop Rep. Dan Bishop on x
    The entire US no-fly list - with 1.5 million+ entries - was found on an unsecured server by a Swiss hacker. Besides the fact that the list is a civil liberties nightmare, how was this info so easily accessible? We'll be coming for answers. https://www.vice.com/...
  • @motherboard @motherboard on x
    The list includes names and birth dates and more than 1.5 million entries, but many of those entries are aliases that all reference the same person. https://www.vice.com/...
  • @paulszoldra Paul Szoldra on x
    A Swiss hacker writes about how easy it was to find an airline's open server and finding a very interesting file on it: NOFLY.csv, a 2019 copy of the @TSA no-fly list, with roughly 1.5 million entries. https://www.dailydot.com/... https://twitter.com/...
  • @jesselynradack @jesselynradack on x
    Asking as an alum of the “No-Fly List”: Is it still largely the names of Muslims, progressive pols & political dissidents? #NoFlyList https://www.vice.com/...
  • @jessmarindavis @jessmarindavis on x
    Ummmmmmm this is big. (Also that list of aliases is gonna be real useful for some OSINT folks...) https://twitter.com/...
  • @realunsweetdee SweetDee on x
    “Located by Swiss hacker known as maia arson crimew, the server, run by U.S. nat'l airline CommuteAir, was left exposed on the public internet. It revealed a vast amount of company data, including private information on almost 1,000 CommuteAir employees.” https://www.dailydot.com…
  • @sunnyright Sunny McSunnyface on x
    It's an old one from 2019 and the person who found it is being responsible and not just posting the list, but the airline has confirmed. @PeteButtigieg, call your office. Again. https://twitter.com/...