FlightAware configuration error leaked user data for years

FlightAware configuration error leaked user data for years

August 19, 2024 at 10:06AM

FlightAware, a Houston-based flight tracking platform, is requesting some users to reset their account passwords due to a data security incident that may have exposed personal information. The incident, caused by a configuration error on January 1, 2021, was discovered on July 25, 2024. Potentially compromised information includes user IDs, passwords, and various personal details. FlightAware has taken remedial action and is providing free identity protection and urging users to reset their passwords as a precaution.

From the meeting notes, the following key takeaways can be generated:

1. FlightAware, a flight tracking platform based in Houston, Texas, experienced a data security incident that may have exposed personal information of its users.
2. The incident occurred on January 1, 2021, due to a configuration error and was only discovered on July 25, 2024, leaving personal user information exposed for more than three years.
3. Potentially compromised data types include user ID, password, email address, full name, billing address, shipping address, IP address, social media account, telephone number, year of birth, last four digits of credit card number, information about aircraft owned, pilot status, industry and title, account activity, and Social Security number (SSN).
4. FlightAware has taken remedial measures to address the configuration error and is prompting all affected users to reset their passwords on their next login.
5. Impacted users are being offered a free-of-charge 24-month identity protection package through Equifax and are advised to report suspicious activity to their local law enforcement authorities.
6. Users are also advised to reset their credentials on other online platforms if they were using the same login information for FlightAware’s platform.

It is important to ensure that all affected users are informed of the incident, provided with necessary support, and given clear instructions on how to protect their personal information.

Full Article