/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: ID codes printed on boarding passes, luggage tags for ~90% of flights let hackers access travelers' personal info, steal reservations, more

Booking a flight has become a simple process thanks to the Internet, and once you have flights secured you can relax, right?

PC Magazine Matthew Humphries

Context & Ripple Effects

This finding lands on a documented runway: Delta had a boarding-pass flaw letting passengers pull up other travelers' passes back in 2014, and by 2015 the FBI and TSA were formally warning airlines about network tampering and intrusions. What the researchers add here is scale — the ID codes printed on passes and luggage tags expose booking data across roughly 90% of flights, turning a per-airline bug into an industry-wide exposure.

It also fits a broader pattern the coverage keeps confirming: a follow-up audit found airlines sharing booking data with third-party trackers and generally weak security practices, and two years later researchers found an e-ticketing flaw at eight-plus airlines including Southwest via intercepted emails. Printed codes are just one more surface in a reservation stack that keeps leaking.

First-order effects

  • Travelers who photograph or discard boarding passes and bag tags hand attackers a working key to their reservation record — personal information, itinerary changes, and booking control — with no airline login required.
  • Airlines' reservation systems inherit the exposure at near-industry scale, since the vulnerable codes appear on passes and tags for about 90% of flights rather than on any single carrier's tickets.

Second-order effects

  • Carriers face pressure to treat the printed code itself as a credential — rotating or masking it — which collides with the operational reality that tags must stay scannable by ground handlers and kiosks.
  • With the FBI and TSA already on record warning airlines about intrusions, findings like this give regulators and security agencies concrete ammunition to push reservation-system audits beyond voluntary compliance.

Third-order effects

  • If code-based identity keeps failing — Delta in 2014, this industry-wide finding, the multi-airline e-ticketing flaw after — the structural exit is removing printable credentials altogether, which is the direction US airports were already moving by 2021 with opt-in facial-recognition ID checks.
  • Repeated reservation-data leaks position passenger data security as a competitive and regulatory differentiator for airlines, the way payment-card security became one for retailers.

The trend: Airline identity verification is drifting from printable, guessable codes toward biometric checkpoints as each generation of reservation-system flaws erodes trust in paper credentials.