Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Sony appears to be testing dynamic pricing on PlayStation games

    Sony appears to be testing dynamic pricing on PlayStation games

    March 7, 2026
    Vizio accounts are becoming Walmart accounts

    Vizio accounts are becoming Walmart accounts

    March 7, 2026
    Apple’s cheap laptop looks like a winner

    Apple’s cheap laptop looks like a winner

    March 7, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats
    Security

    A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

    News RoomBy News RoomAugust 2, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

    An airline leaving all of its passengers’ travel records vulnerable to hackers would make an attractive target for espionage. Less obvious, but perhaps even more useful for those spies, would be access to a premium travel service that spans 10 different airlines, left its own detailed flight information accessible to data thieves, and seems to be favored by international diplomats.

    That’s what one team of cybersecurity researchers found in the form of Airportr, a UK-based luggage service that partners with airlines to let its largely UK- and Europe-based users pay to have their bags picked up, checked, and delivered to their destination. Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US.

    “Anyone would have been able to gain or might have gained absolute super-admin access to all the operations and data of this company,” says Himanshu Pathak, CyberX9’s founder and CEO. “The vulnerabilities resulted in complete confidential private information exposure of all airline customers in all countries who used the service of this company, including full control over all the bookings and baggage. Because once you are the super-admin of their most sensitive systems, you have have the ability to do anything.”

    Airportr’s CEO Randel Darby confirmed CyberX9’s findings in a written statement provided to WIRED but noted that Airportr had disabled the vulnerable part of its site’s backend very shortly after the researchers made the company aware of the issues last April and fixed the problems within a few day. “The data was accessed solely by the ethical hackers for the purpose of recommending improvements to Airportr’s security, and our prompt response and mitigation ensured no further risk,” Darby wrote in a statement. “We take our responsibilities to protect customer data very seriously.”

    CyberX9’s researchers, for their part, counter that the simplicity of the vulnerabilities they found mean that there’s no guarantee other hackers didn’t access Airportr’s data first. They found that a relatively basic web vulnerability allowed them to change the password of any user to gain access to their account if they had just the user’s email address—and they were also able to brute-force guess email addresses with no rate limitations on the site. As a result, they could access data including all customers’ names, phone numbers, home addresses, detailed travel plans and history, airline tickets, boarding passes and flight details, passport images, and signatures.

    By gaining access to an administrator account, CyberX9’s researchers say, a hacker could also have used the vulnerabilities it found to redirect luggage, steal luggage, or even cancel flights on airline websites by using Airportr’s data to gain access to customer accounts on those sites. The researchers say they could also have used their access to send emails and text messages as Airportr, a potential phishing risk. Airportr tells WIRED that it has 92,000 users and claims on its website that it has handled more than 800,000 bags for customers.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleWatch Our Livestream Replay: Inside Katie Drummond’s Viral Interview With Bryan Johnson
    Next Article The FBI’s Jeffrey Epstein Prison Video Had Nearly 3 Minutes Cut Out

    Related Posts

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    December 6, 2025
    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    December 5, 2025
    Your Data Might Determine How Much You Pay for Eggs

    Your Data Might Determine How Much You Pay for Eggs

    December 4, 2025
    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    December 4, 2025
    This Hacker Conference Installed a Literal Antivirus Monitoring System

    This Hacker Conference Installed a Literal Antivirus Monitoring System

    December 4, 2025
    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    December 4, 2025
    Our Picks
    Vizio accounts are becoming Walmart accounts

    Vizio accounts are becoming Walmart accounts

    March 7, 2026
    Apple’s cheap laptop looks like a winner

    Apple’s cheap laptop looks like a winner

    March 7, 2026
    The Corvette ZR1X hybrid can outpace million-dollar sports cars for a fraction of the cost

    The Corvette ZR1X hybrid can outpace million-dollar sports cars for a fraction of the cost

    March 7, 2026
    DJI will pay K to the man who accidentally hacked 7,000 Romo robovacs

    DJI will pay $30K to the man who accidentally hacked 7,000 Romo robovacs

    March 6, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Grammarly is using our identities without permission News

    Grammarly is using our identities without permission

    By News RoomMarch 6, 2026

    Grammarly’s “expert review” feature offers to give users writing advice “inspired by” subject matter experts,…

    Valve’s Steam Machine may not launch this year

    Valve’s Steam Machine may not launch this year

    March 6, 2026
    The Trump administration says it can’t process tariff refunds because of computer problems

    The Trump administration says it can’t process tariff refunds because of computer problems

    March 6, 2026
    You can already save up to  on the new M4 iPad Air

    You can already save up to $50 on the new M4 iPad Air

    March 6, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.