Technologist Mag
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

How We Test Air Purifiers and What You Should Consider When Buying

18 August 2025

WIRED Takes You Back to School

18 August 2025

The Plan to Turn the Caribbean’s Glut of Sargassum Into Biofuel

18 August 2025

AI Is Designing Bizarre New Physics Experiments That Actually Work

17 August 2025

Pebblebee Is Getting Serious About Personal Safety Tracking

17 August 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Technologist Mag
SUBSCRIBE
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release
Technologist Mag
Home » A Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats
Tech News

A Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

By technologistmag.com24 July 20253 Mins Read
Share
Facebook Twitter Reddit Telegram Pinterest Email

An airline leaving all of its passengers’ travel records vulnerable to hackers would make an attractive target for espionage. Less obvious, but perhaps even more useful for those spies, would be access to a premium travel service that spans 10 different airlines, left its own detailed flight information accessible to data thieves, and seems to be favored by international diplomats.

That’s what one team of cybersecurity researchers found in the form of Airportr, a UK-based luggage service that partners with airlines to let its largely UK- and Europe-based users pay to have their bags picked up, checked, and delivered to their destination. Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US.

“Anyone would have been able to gain or might have gained absolute super-admin access to all the operations and data of this company,” says Himanshu Pathak, CyberX9’s founder and CEO. “The vulnerabilities resulted in complete confidential private information exposure of all airline customers in all countries who used the service of this company, including full control over all the bookings and baggage. Because once you are the super-admin of their most sensitive systems, you have have the ability to do anything.”

Airportr’s CEO Randel Darby confirmed CyberX9’s findings in a written statement provided to WIRED but noted that Airportr had fixed the vulnerabilities a few days after the researchers made the company aware of the issues last April. “The data was accessed solely by the ethical hackers for the purpose of recommending improvements to Airportr’s security, and our prompt response and mitigation ensured no further risk,” Darby wrote in a statement. “We take our responsibilities to protect customer data very seriously.”

CyberX9’s researchers, for their part, counter that the simplicity of the vulnerabilities they found mean that there’s no guarantee other hackers didn’t access Airportr’s data first. They found that a relatively basic web vulnerability allowed them to change the password of any user to gain access to their account if they had just the user’s email address—and they were also able to brute-force guess email addresses with no rate limitations on the site. As a result, they could access data including all customers’ names, phone numbers, home addresses, detailed travel plans and history, airline tickets, boarding passes and flight details, passport images, and signatures.

By gaining access to an administrator account, CyberX9’s researchers say, a hacker could also have used the vulnerabilities it found to redirect luggage, steal luggage, or even cancel flights on airline websites by using Airportr’s data to gain access to customer accounts on those sites. The researchers say they could also have used their access to send emails and text messages as Airportr, a potential phishing risk. Airportr tells WIRED that it has 92,000 users and claims on its website that it has handled more than 800,000 bags for customers.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleElden Ring Nightreign, Shadow Of The Erdtree Hit Major Sales Milestones
Next Article Five Reasons Why Samsung Galaxy S24 Ultra is Still the Ultimate Flagship in 2025 Under Rs 1 Lakh

Related Articles

How We Test Air Purifiers and What You Should Consider When Buying

18 August 2025

WIRED Takes You Back to School

18 August 2025

The Plan to Turn the Caribbean’s Glut of Sargassum Into Biofuel

18 August 2025

AI Is Designing Bizarre New Physics Experiments That Actually Work

17 August 2025

Pebblebee Is Getting Serious About Personal Safety Tracking

17 August 2025

The Best Posture Correctors to Straighten You Out

17 August 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Don't Miss

WIRED Takes You Back to School

By technologistmag.com18 August 2025

© 2025 Condé Nast. All rights reserved. WIRED may earn a portion of sales from…

The Plan to Turn the Caribbean’s Glut of Sargassum Into Biofuel

18 August 2025

AI Is Designing Bizarre New Physics Experiments That Actually Work

17 August 2025

Pebblebee Is Getting Serious About Personal Safety Tracking

17 August 2025

The Best Posture Correctors to Straighten You Out

17 August 2025
Technologist Mag
Facebook X (Twitter) Instagram Pinterest
  • Privacy
  • Terms
  • Advertise
  • Contact
© 2025 Technologist Mag. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.