CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3299

As cited

Copy frozen at (site build).

breaches incidents

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.

Frontier Airlines experienced multiple data security incidents in 2024, beginning with a breach disclosed June 16 by a researcher who demonstrated that boarding passes contained inadequate security controls. A second incident followed, and a third hacking group has claimed responsibility for an additional compromise of the airline.

Why it matters: Practitioners managing airline or travel sector infrastructure should assess whether similar boarding pass or customer data exposure vulnerabilities affect their systems, and review incident response processes given the apparent pattern of multiple breaches at a single organization.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.

Frontier Airlines has faced at least three alleged data security incidents in 2026. A threat actor named BobDaHacker published details about a breach on June 16, and a separate group has since claimed to have compromised the airline as well, with the incidents reportedly linked to unpatched known vulnerabilities.

Why it matters: Airline passengers and employees whose data may have been exposed in these incidents should monitor for fraud; security teams should audit their own vulnerability management processes to ensure known exploits do not remain unpatched in production systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary