A look at airlines' weak data security practices, including sharing booking data with third-party trackers
I asked my wife if it is alright if her Date of Birth is known to a stranger. Only if they send me a birthday gift, she joked. What about your passport number? She lowered the book she was reading. Tweets: @geidies Tweets: Sebastian Geidies / @geidies : 1/2 “you click on manage preferences to select a seat or meal .. or Check-in to your flight, your Booking ID and Last name is passed on to approximately 14 different third-party trackers...”—@konarkmodi http://medium.com/...
Context & Ripple Effects
This finding lands on top of a multi-year record of airline data exposure: researchers previously showed that ID codes printed on boarding passes and luggage tags could let hackers pull travelers' personal details, and later found an e-ticketing flaw at eight-plus airlines including Southwest that exposed sensitive information via intercepted emails. Delta had an earlier incident where passengers could view other people's boarding passes.
What Konark Modi and Sebastian Geidies add is the routine, everyday layer: the check-in and seat-selection pages themselves, which hand a booking ID and last name to roughly 14 third-party trackers per interaction. The irony is sharp given that airlines have spent years restricting data sharing with fare-comparison sites to keep bookings on their own properties — guarding the commercial channel while the security channel leaks.
First-order effects
- Passengers using manage-preferences, seat-selection, or check-in flows have their booking ID and last name transmitted to approximately 14 third-party trackers each time, with no direct relationship to those recipients.
- The named airlines now face the gap between their own data-sharing restrictions on fare-comparison sites and the uncontrolled leakage happening inside their own booking funnels.
Second-order effects
- The hotel sector shows the same failure mode at scale — Symantec found roughly 67% of 1,500 hotel sites across 54 countries leaking guest booking data to ad and analytics services — meaning ad-tech networks accumulate cross-industry travel profiles from both airlines and hotels.
- As these findings accumulate, airlines' proprietary booking channels — built partly to avoid sharing data with intermediaries — become the liability rather than the asset, inviting privacy scrutiny of every script embedded in the purchase path.
Third-order effects
- If the pattern holds across boarding passes, e-tickets, and now tracker-laden check-in pages, the structural issue is that travel booking was architected around loosely governed third-party integrations, making passenger identity data a systemic exposure rather than a series of isolated bugs — the kind of pattern that historically draws regulator attention to the whole sector rather than single carriers.
The trend: Travel booking infrastructure is leaking passenger identity data to third parties faster than airlines and hotels can secure it, turning routine transactions into a standing privacy exposure.