FlightAware
Disclosed Aug 13, 20242 years agoConfirmed
FlightAware configuration error exposes customer data including SSNs
Flight tracking site FlightAware said a configuration error identified on July 25, 2024 exposed customer names, emails, addresses, IP addresses, phone numbers, partial card numbers, aircraft and pilot details and, for some, Social Security numbers.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Aug 13, 2024 |
| Discovered | Jul 25, 2024 |
| Happened | Jan 1, 2021 |
| Attack | Exposed data |
| Data exposed | Names, Emails, Addresses, IP addresses, Phone numbers, Social Security numbers, Payment cards, Other |
| Sector | Transport · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: FlightAwareoag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: FlightAwareatg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: FlightAwarejustice.oregon.gov · Official notice | Official notice |
| FlightAware warns that some customers' info has been exposed, including Social Security numberstechcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Aug 13, 2024 | |
| Washington AGresidents of WA | Aug 13, 2024 | 1,407 |
| Oregon DOJresidents of OR | Aug 13, 2024 | 2,000,000 |
| Researchtotal | Aug 19, 2024 |
History of this record
- 2026-09-25 · sector: other to transport · seed source
- 2026-09-25 · attack: hacking to misconfiguration · seed source
- 2026-09-25 · data_types: [] to ["names","emails","addresses","ip-addresses","phone","ssn","payment-card","other"] · seed source
- 2026-09-25 · summary: empty to Flight tracking site FlightAware said a configuration error identified on July 25, 2024 exposed customer names, emails, addresses, IP addresses, phone numbers, partial card numbers, aircraft and pilot details and, for some, Social Security · seed source
- 2026-09-25 · title: empty to FlightAware configuration error exposes customer data including SSNs · seed source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · discovered: empty to 2024-07-25 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.