The Airlines Reporting Corporation (ARC), a data broker owned by major airlines, has announced it will discontinue its Travel Intelligence Program (TIP), which sold hundreds of millions of customer travel records to US government agencies. This decision follows a letter from ARC's CEO to lawmakers, prompted by bipartisan pressure after revelations that the Internal Revenue Service (IRS) accessed ARC's extensive travel database without a warrant, violating federal law and agency policy. The database included detailed information on individuals' flight itineraries and credit card transactions, covering approximately 722 million ticket transactions over a 39-month period.
Lawmakers criticized ARC for enabling 'prospective surveillance' by allowing government agencies to set up automated alerts for new matching reservations, effectively bypassing higher legal standards for monitoring future activity. The controversy intensified after it was revealed that the IRS did not conduct a privacy impact assessment or legal review before purchasing the data. ARC's move to halt the TIP comes amid ongoing scrutiny over the privacy implications of selling such sensitive travel data to government entities without adequate oversight or legal safeguards.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
ARC CEO Lauri Reishus informed lawmakers that the company would discontinue the Travel Intelligence Program, which had provided government agencies access to large-scale airline ticketing and travel records. The move followed reporting and congressional scrutiny over warrantless government access to the data.
A bipartisan group of U.S. lawmakers pressed airline CEOs to shut down ARC's Travel Intelligence Program after scrutiny of government access to the travel database. They also criticized the system's ability to support prospective surveillance through alerts on future reservations.
The IRS obtained access to ARC's Travel Intelligence Program data without completing required privacy and legal reviews, including determining whether a warrant was needed. Sen. Ron Wyden later said the IRS admitted the purchase violated federal law and IRS policy.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.