Spying on People Through Airportr Luggage Delivery Service

Security Update News

Update Information

Title Spying on People Through Airportr Luggage Delivery Service
Update ID SCHNEIER:B6DE36D789B95F711C0A7841B2B72869
Type schneier
Published 2025-08-01T11:07:28
Last Updated 2025-07-30T16:10:57

Security Impact

Severity NONE

AI Analysis

AI Description A vulnerability in Airportr’s website allows attackers to access sensitive user information, including travel plans and personal data. This could enable unauthorized access to administrative privileges, potentially leading to theft or redirection of luggage. The issue affects users globally, including high-profile individuals like government officials.
AI Severity Critical
AI Vendor Airportr
AI Product Airportr
AI Version Unknown

Update Details

Airportr is a service that allows passengers to have their luggage picked up, checked, and delivered to their destinations. As you might expect, it’s used by wealthy or important people. So if the company’s website is insecure, you’d be able to spy on lots of wealthy or important people. And maybe even steal their luggage.

> Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US.
>
> “Anyone would have been able to gain or might have gained absolute super-admin access to all the operations and data of this company,” says Himanshu Pathak, CyberX9’s founder and CEO. “The vulnerabilities resulted in complete confidential private information exposure of all airline customers in all countries who used the service of this company, including full control over all the bookings and baggage. Because once you are the super-admin of their most sensitive systems, you have have [sic] the ability to do anything.”

View Advisory Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.