TSA’s ‘No Fly List’ Data Left Up for Grabs on Unprotected Server: Report
A Swiss hacker stumbled across the trove, reportedly located on a server run by the U.S. national airline CommuteAir.

David McNew/Getty Images
A Swiss hacker stumbled across an unprotected server maintained by a U.S. national airline that included the private information of “hundreds of thousands” of people registered on the American government’s federal “No Fly List” and terrorism database, according to the Daily Dot. The identities of nearly 1,000 employees with the airline, CommuteAir, were also compromised, the outlet reported. The hacker, maia arson crimew, told the Daily Dot that the exposed infrastructure could have allowed a bad actor to “completely own” the airline. The server was taken offline prior to publication, after the Daily Dot flagged it to CommuteAir, which told the outlet in a statement that the server was used for testing and development purposes. In its own statement, the TSA said that it was “aware of a potential cybersecurity incident with CommuteAir, and we are investigating in coordination with our federal partners.”
Register below to read this article for free or subscribe
to unlock unlimited access to The Daily Beast.
Monthly
$1
First month then $5.99/month
Annual
$35
First year then $59.99/year
Premium
$79
First year then $119.99/year
*Substack access provided by the next business day, using your subscription email. Choosing the Premium plan constitutes your permission to share your subscription email with Substack and your agreement to Substack’s Privacy Policy.
Already have an account? Sign In
Looks like you already have a subscription!
You're all set!
Thanks for subscribing.