Researchers discover e-ticketing flaw at 8+ airlines, including Southwest, that would let hackers access sensitive info by intercepting emails to travellers
Our threat researchers discovered that these airlines … Eduard Kovacs / SecurityWeek : Check-in Links Sent by Several Airlines Expose Passenger Data Davey Winder / Forbes : Multiple Airlines Exposed To Check-In Hijack Threat — What Passengers Should Do Next Tweets: Zack Whittaker / @zackwhittaker : Today in buried ledes: You have to be on the same network as the victim. http://www.cyberscoop.com/... Jeff Stone / @jeffstone500 : There's no sign this vulnerability has been exploited (nor would there be) but attackers **could** access seating information and re-assign you to a different flights (in some scenarios). It's the latest example of convenience beating security. https://www.cyberscoop.com/... pic.twitter.com/lpNxyO10Ub Jeff Stone / @jeffstone500 : If you're flying soon, think twice about clicking that check-in link in your inbox. Eight airlines are aware the links are unencrpyted, and spewing personal information. Three said they “take security seriously,” but there's no sign of a fix. https://www.cyberscoop.com/... pic.twitter.com/QBEP1U8lpU
Context & Ripple Effects
This disclosure extends a five-year pattern of airline passenger-data exposures rather than opening a new front. In 2014, Delta's boarding-pass flaw let passengers pull up other travelers' passes; in 2017, researchers showed ID codes printed on boarding passes and luggage tags for roughly 90% of flights could be used to access personal information and steal reservations. A 2018 analysis then documented airlines' broader weak practices, including sharing booking data with third-party trackers.
What changed today is the delivery channel: instead of printed codes or mis-scoped web sessions, the vulnerability lives in the unencrypted check-in links airlines email to travellers at 8+ carriers, Southwest among them. The mitigating detail from the reporting — an attacker must be on the same network as the victim — limits who can act on it, but the affected surface is every emailed itinerary link those airlines send.
First-order effects
- Southwest and the other named airlines face immediate remediation pressure on their e-ticketing pipelines, since every emailed check-in link currently exposes seating information to anyone positioned to intercept it.
- Passengers on shared networks — airport Wi-Fi, hotels, offices — are the directly exposed population, with attackers able not only to read booking details but re-assign seats or move travellers to different flights.
Second-order effects
- The disclosure strengthens the case for structured vulnerability programs like United's mileage-point bug bounty, putting peer airlines that lack equivalent channels at reputational disadvantage each time researchers go public.
- Airlines' wider booking-data handling — already flagged over third-party tracker sharing — gets pulled into the same scrutiny, since each new flaw makes 'isolated incident' framing harder to sustain.
Third-order effects
- If the pattern holds, airline reservation systems will be pushed toward treating emailed links and printed identifiers as authenticated credentials by default — encrypted, expiring, and bound to the traveller — rather than convenience URLs.
- Recurring researcher disclosures across boarding passes, apps, and now email may draw regulators into passenger-data security the way the FBI and TSA's earlier warnings about airline network tampering previewed official concern.
The trend: Airline passenger-data security keeps failing at the identifier layer — printed codes, session tokens, now emailed check-in links — with researchers surfacing the same class of flaw faster than carriers redesign their booking plumbing.