A security researcher disclosed multiple vulnerabilities in Frontier Airlines’ website and mobile booking API that allegedly exposed sensitive passenger records using information printed on a boarding pass. According to the reports, a six-character booking code (PNR) and, in many cases, a passenger’s last name were enough to retrieve home addresses, phone numbers, email addresses, dates of birth, passport details, TSA PreCheck or Known Traveler Numbers, Frontier Miles numbers, billing details, and partial payment-card data. One earlier flaw reportedly allowed booking data to be accessed from the PNR alone before Frontier partially remediated it.
The researcher said Frontier was notified in early March under a 90-day disclosure process, but key issues were still reportedly live more than 100 days later. The reports say some data remained hidden only in the user interface while still being exposed through page source or API responses in areas such as Manage My Booking and passenger-edit functions, and that one attempted fix may have revealed even more information. The exposure raised risks including identity theft, stalking, misuse of trusted traveler information, and easier reconstruction of payment-card numbers from disclosed BIN, expiration, billing data, and last four digits.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Frontier fixed one endpoint that had exposed booking data from a PNR alone, but other vulnerabilities reportedly remained. According to the reporting, the partial remediation did not resolve the broader exposure and in one case allegedly led to even more information being revealed in source code or API responses.
As of June 18, 2026, the main vulnerabilities were still reportedly unpatched, leaving passport details, contact information, TSA PreCheck data, and partial payment-card information exposed through Frontier's systems. The reports also state Frontier had not publicly responded by that point.
The researcher contacted Frontier again as part of a 90-day disclosure process after the initial report. This follow-up indicated the vulnerabilities had not been fully remediated.
Security researcher BobDaHacker notified Frontier Airlines about multiple vulnerabilities that exposed passenger data through its API and booking-management functionality. The issues reportedly allowed access to sensitive records using booking information from a boarding pass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.