- Sputnik International
World
Get the latest news from around the world, live coverage, off-beat stories, features and analysis.

Exposed: German Air Passengers’ Data Easily Accessible Since 2011

© AFP 2023 / Christof StachePassengers queue at a Lufthansa counter at the Franz-Josef-Strauss-airport in Munich, southern Germany, on April 27, 2016.
Passengers queue at a Lufthansa counter at the Franz-Josef-Strauss-airport in Munich, southern Germany, on April 27, 2016. - Sputnik International
Subscribe
Millions of credit card numbers and flight data belonging to airline passengers have been vulnerable and easy to access since 2011 due to online security gaps revealed at Germany's largest wholesale ticket dealer.

The personal data of millions of travelers including the itineraries, names and addresses as well as payment information has been accessible online for years.

In the wake of a series of terror attacks across Germany this latest security breach has been revealed at a difficult time and was reported by Sueddeutsche Zeitung on Monday.

No sophisticated IT skills were needed to retrieve the data and it could be accessed with minimal effort, according to Sueddeutsche Zeitung.

​According to an investigation by the newspaper, the data vulnerability was down to huge security gaps in the computer systems of Berlin-based airline ticket wholesaler Aerticket. The company provides tickets for thousands of corporate clients, including German travel agencies, online booking portals and ticket search engines.

Aerticket AG is the largest independent airline ticket wholesaler in Germany. Such companies serve as intermediaries between airlines and travel agencies or booking portals, as issuing tickets normally requires a costly license from the International Air Transport Association (IATA).

Booking a flight on one of Aerticket's partners included receiving an email with a link to retrieve and download a passenger's itinerary receipt, Sueddeutsche Zeitung wrote. Every link to an itinerary receipt ended with an eight-digit number, but the company's failure was that the documents were not protected.

​The eight digits at the end of each link could be changed manually by anyone, allowing the possibility of a user to jump to other travelers' tickets, invoices, routes and credit card numbers. 

Passengers - Sputnik International
MEPs Approve Passenger Name Record Scheme Despite Human Rights Fears

While other flight portals use randomly generated codes that include numbers and letters, that was not the case at Aerticket, the newspaper reported.

The files were accessible and contained passengers' names and addresses, departure airports, airline names as well as prices at which tickets were booked. In some cases, even passenger dates of births were available.

Aerticket responded quickly to the newspaper report and eliminated the vulnerability within hours. The company also admitted the gap had existed since 2011 with some 1.5 million bookings made since then.

A Belgian soldier accompanies passengers at Brussels' Zaventem airport following Tuesday's bomb attacks in Brussels, Belgium, March 23, 2016. - Sputnik International
France Calls for End to Passenger Data Standoff After Brussels Bombings

The company said the security gap was not exploited by criminals, but Berlin data protection authorities said they will investigate the case, a process that may take up to several months.

Around 14,500 corporate customers in Germany work with Aerticket but European passengers' data could have been accessible as well. German travel portal flight24.de, also an Aerticket customer, had national websites in Austria, the UK, the Netherlands, France, Italy and Spain.

Newsfeed
0
To participate in the discussion
log in or register
loader
Chats
Заголовок открываемого материала