惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
IT之家
IT之家
博客园 - Franky
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Help Net Security
V
V2EX
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
博客园 - 叶小钗
J
Java Code Geeks
博客园 - 【当耐特】
月光博客
月光博客
爱范儿
爱范儿
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件

Gadget Review

Bernie Sanders Wants You to Own Half of OpenAI - And He's Not Kidding - Gadget Review California Bill Strikes Back Against Disappearing Video Games - Gadget Review Japan Cracks 6G's Speed Barrier With 112 Gbps Wireless Breakthrough - Gadget Review 31 Amazon Kitchen Tools and Gadgets That Make Prep Time a Breeze The 559-Mile Mic-Drop: Why BMW’s New i3 Just Made Tesla’s Range Look Like A Toy - Gadget Review 20 Genius Camping Gadgets That Will Help Make Summer Camping Easier Tesla Patents Transform Glass Roofs Into Smart Air Conditioners - Gadget Review Is Anthropic’s “Benefit Corp” Structure An Investor’s Worst Nightmare? - Gadget Review How An AI Weather Startup Just Beat the World’s Greatest Supercomputers - Gadget Review Dell's New XPS 13 Is Directly Targeting The MacBook Neo - Gadget Review 13 Smart Home Gadgets for True Local Control (No Cloud Needed!) Florida Sues OpenAI and CEO Sam Altman - Why Florida Is Treating AI Chatbots as "Hazardous Products" - Gadget Review Malaysia’s Scorched-Earth Policy Against Under-16 Social Media Access - Ban Carries Fines Up To $2.5 Million - Gadget Review PlayStation's Wireless Fight Stick and Latest Gaming Monitor Hits This August - Gadget Review How Meta's Chatbot Handed Over Million-Dollar Instagram Accounts To Attackers - Gadget Review 11 Home Security Gadgets That Help Safeguard Your Sanctuary Engineer Builds AI-Powered Laser System That Targets & Hunts Mosquitoes at Home - Gadget Review DuckDuckGo's No-AI Search Extensions Surge as Users Flee Google's AI Overhaul - Gadget Review Google Wants to Release 32 Million "Infected" Mosquitoes Into The Wild - Gadget Review Nvidia Is Bringing AI Power To Your Desk With New Superchip - Gadget Review Tech CEOs Are Using AI as the Perfect Scapegoat for Mass Layoffs - Gadget Review Wix Cuts 1,000 Jobs, Citing AI Evolution and Currency Pressures - Gadget Review Teen's Bluetooth Speaker Named "BOMB" Forces Flight U-Turn Mid-Atlantic - Gadget Review China's Humanoid Robots Sort 1,200 Postal Packages Per Hour - Gadget Review California Senate Passes Historic Ban on AI Chatbot Toys - Gadget Review Professor Declares War on AI: Will Fail Any Student Who Uses It - Gadget Review UK Military Looks At Allowing Lethal Strikes With Zero Human Intervention - Gadget Review Chinese EVs Are Tanking in Value - Gadget Review Japanese Researchers Create Chip That Could Run 1,000x Faster, Near-Zero Heat - Gadget Review Total Immobility: Why A Single Targeted Cyberattack Could Leave Every EV In Your City Stranded - Gadget Review
Your Frontier Boarding Pass May Be Leaking Your Passport ...
Alex Barrientos · 2026-06-19 · via Gadget Review

Frontier’s mobile API leaked passport numbers and near-complete card data to anyone with a booking code and last name

A security researcher found that two pieces of info printed on every Frontier boarding pass unlock passports, home addresses, and near-complete credit card data. The airline’s response after three months? A model airplane.

Travelers who posted a boarding pass photo at the gate—or left a crumpled one in the seatback pocket—may have handed attackers everything needed to access their most sensitive personal data. Security researcher BobDaHacker documented that Frontier’s mobile API returns a full internal booking record—passport numbers, home addresses, children’s dates of birth, near-complete credit card details—when queried with just a six-character booking code and a last name. Both are printed in plain text on every boarding pass, according to independent reporting from TechSpot and Tom’s Hardware.

What Actually Gets Exposed

The API returns a disturbingly complete dossier on every passenger tied to a booking.

For every person on the reservation, including minors, the API returns:

  • Full home address, email, phone number, and date of birth
  • Complete, unmasked passport number, issuing country, expiration date, and nationality
  • Known Traveler Number (the TSA PreCheck identifier)
  • Credit card first six digits, last four digits, expiration date, cardholder name, full billing address, and payment history with authorization codes

That “partial” card data is practically a complete card number. The first six and last four digits leave only five unknown middle digits—roughly 100,000 combinations. Automated tools work through that range trivially. Add the full billing address, which satisfies most merchants’ Address Verification checks, and the CVV is the only remaining secret. According to BobDaHacker’s analysis, many online merchants don’t strictly require it. These kinds of oversights are part of a long history of tech scandals in which corporate data failures leave millions of users exposed. “That’s it. That’s the security.” — BobDaHacker, describing an API authentication system reduced to two data points printed on every boarding pass

Three Months of Silence and a Model Airplane

Frontier let a formal disclosure deadline expire without response, leaving the most severe flaws live in production.

BobDaHacker first notified Frontier on March 3. A formal 30-day deadline was set for June 12. Frontier reportedly let it pass without response. The airline’s only documented action: patching one lower-severity endpoint and mailing the researcher a model airplane. As of the mid-June public disclosure, the passport- and card-dumping API remained exploitable. No public statement from Frontier. No remediation timeline. Cases like this echo the methods used in a covert surveillance app built to harvest personal data without users’ knowledge.

A former Frontier employee, writing after the disclosure went public, described the booking engine as “a mess of generated config and code that only one person was senior enough to touch.” This is the codebase equivalent of still running Windows XP because nobody remembers the admin password—except it’s handling your passport data.

Treat boarding passes like bank statements: shred them, and stop posting them online. Monitor your card activity if you’ve flown Frontier recently, and consider placing a fraud alert if you’re concerned. This isn’t just one budget carrier’s problem—it’s what happens when the industry bolts modern APIs onto legacy systems and calls it secure.