A misconfigured, publicly accessible development server operated by regional airline CommuteAir exposed an outdated 2019 version of the U.S. no-fly list along with personal information for roughly 900 employees. The exposure was reportedly discovered by Swiss hacker maia arson crimew, who found a file named NoFly.csv containing more than 1.5 million records, including names and birth dates of people identified as having suspected ties to terrorist organizations; reports noted the total was likely inflated by aliases and duplicate-style entries.
CommuteAir confirmed the database was legitimate, took the server offline, and said it reported the incident to the Cybersecurity and Infrastructure Security Agency. The leaked file was described as a subset of the broader U.S. Terrorist Screening Database maintained by the DOJ, FBI, and Terrorist Screening Center, and the disclosure renewed criticism from civil liberties advocates who argue the watchlisting system is opaque, error-prone, and disproportionately affects Muslims and people of Arab, Middle Eastern, or South Asian descent.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
CommuteAir confirmed the legitimacy of the exposed database, said the development server had been taken offline, and reported the incident to the Cybersecurity and Infrastructure Security Agency. This marked the company's official response to the exposure.
Swiss hacker maia arson crimew reportedly found the unprotected CommuteAir development server and identified the leaked no-fly list data on it. The discovery was first reported publicly in media coverage published on January 19, 2023.
A publicly accessible misconfigured development server operated by CommuteAir exposed an outdated 2019 version of the U.S. no-fly list along with personal data belonging to about 900 employees. The exposed file, labeled "NoFly.csv," reportedly contained more than 1.5 million entries, including names and birthdates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.