TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Research/How to do it

Your Flight Booking Code Can Be Used By Hackers To Access Your Personal Info

Paul Balo by Paul Balo
January 3, 2017
in Research/How to do it, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • One of the comforts the internet has brought us is the fact that we can book flights anywhere and anytime and even choose where we want...
  • But like every online process, even your flight bookings could be subject to hacking.
  • Researchers Karstein Nohl and Nemanja Nikodejevic from German security firm Security Research Labs published just how easy it is to break into travel booking systems.

One of the comforts the internet has brought us is the fact that we can book flights anywhere and anytime and even choose where we want to sit on that flight. But like every online process, even your flight bookings could be subject to hacking.

Researchers Karstein Nohl and Nemanja Nikodejevic from German security firm Security Research Labs published just how easy it is to break into travel booking systems. The report noted that the three largest Global Distributed Systems (GDS) handling such reservations are vulnerable. “Today’s GDSs go back to the 70s and 80s, built around mainframe computers and leased lines. The systems have since been interwoven with web services, but still lack several web security best practices.” Amadeus, Sabre, and Travelport according to the report handle over 90 percent of global flight reservations and their set up dates back to the 70s.

 

So here’s the challenge. Each time you book a flight you are given a unique six digit code which is also knows as a PNR (Passenger Name Record) which is printed on your boarding pass. It’s so public that just about anyone can get a snapshot and if it’s a hacker, they can access all of your personal information including your home address and bank card number, frequent flyer number and IP address used in booking the ticket among others.

With respect to authentication, the researchers said the GDS and airline websites don’t even limit the number of times you can check codes and this means hackers don’t even need to employ brute force to run through the database in order to dig out valid codes. “While the rest of the Internet is debating which second and third factors to use, GDSs do not offer a first authentication factor. Instead, the booking code (aka PNR Locator, a 6-digit alphanumeric string such as 8EI29V) is used to access and change travelers’ information.”

Perhaps the worst part of this it is that these unique codes are serially assigned thereby making it much easier for hackers to locate just about anyone’s information they wish.

To protect yourself, the best shot you’ve got is to not reveal the PNR on your tickets to anyone. The other thing GDS can do is upgrade their entire system to meet modern day threats and probably do away with the six digit codes they currently give. If you think this is not a big deal, then maybe imagine a scenario where you get to the airport only to find out that that your flight booking has just been cancelled.

So here’s the challenge. Each time you book a flight you are given a unique six-character code—known as a Passenger Name Record (PNR)—which is printed on your boarding pass and often embedded in its barcode. It’s so public that anyone with a phone camera can capture it, and if that “anyone” is a hacker they can unlock your personal details: home address, card data, frequent-flyer number, even the IP address used to buy the ticket.

To make matters worse, most airline and GDS sites historically placed no limit on how many times an attacker could test PNRs, meaning brute-force look-ups scarcely broke a sweat. “While the rest of the internet is debating which second and third factors to use, GDSs do not offer a first authentication factor,” the researchers wrote at the time. Perhaps the worst part is that PNRs are assigned sequentially, so criminals can narrow their search to codes issued in the past few days and harvest fresh records in bulk.

What has (and hasn’t) changed since 2017

  • Better—though still optional—lock-downs. Most major carriers now hide the PNR on mobile boarding passes and automatically mask it inside QR codes, yet those barcodes remain easy to scan with freeware apps.

    Also worth reading
    GitHub Confirms Hackers Stole Data From About 3,800 Internal Repositories KongTuke Hackers Exploits Microsoft Teams To Breach Companies New Linux Zero-Day Flaw ‘Dirty Frag’ With Root Access To All Major Distributions Iran-Linked Hackers Are Actively Disrupting US Infrastructure — And It’s Getting Worse Cisco Patches Critical Flaws That Could Let Hackers Take Over Systems Without Login Critical Vulnerability In Microsoft Authenticator Exposes Users To Token Theft
  • Biometrics on the horizon. IATA’s One ID initiative, formally adopted in 2024, lets travellers clear each airport touch-point with a live facial match instead of presenting a code at all. Trials in Doha, Amsterdam and Los Angeles suggest boarding-pass scans could disappear within three years. 

  • Digital travel wallets. The EU’s forthcoming Digital Identity Wallet and the ICAO-backed “Digital Travel Credential” aim to store a cryptographically signed journey token on your phone—making the plain-text PNR obsolete for anyone flying into or across Europe by late-2026. 

  • Persistent breaches. Even as new tech rolls out, 2023–24 saw multiple lawsuits alleging that Sabre and other suppliers failed to encrypt sensitive data at rest. The message is clear: incremental fixes coexist with decades-old infrastructure.

How to protect yourself right now

  • Treat your boarding pass like cash. Shred paper copies; avoid posting “airport selfies” that show the barcode.

  • Use airline apps over e-mail PDFs. Mobile wallets hide the PNR by default and can be wiped remotely if your phone goes missing.

  • Opt in to two-factor where offered. A growing list of carriers (e.g., Lufthansa, United, Emirates) now supports one-time passcodes for itinerary changes.

  • Lobby with your wallet. Choose airlines that have joined One ID or equivalent biometric pilots; every check-in you complete without flashing a PNR makes the old system a little less valuable to attackers.

Until the industry completes its shift to biometric or wallet-based credentials, the humble six-digit locator remains the weak link. That means a single careless selfie, or a boarding pass left in the seat-back pocket, is still enough for a bad actor to cancel your flight—or worse—before you reach the gate. For now, vigilance beats convenience; keep that code out of sight, and hope the travel giants hurry up with the 21st-century overhaul they started talking about nearly a decade ago.

This article was updated in 2025 to reflect some recent developments

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • google-flight-deals
    Google Adds AI to Flight Deals Amid Antitrust Pressure
  • smoobu_guides_booking-scaled
    Booking.com Confirms Data Breach, South African…
  • 1200x800 (1)
    Tech Issue Fixed, United Airlines Restarts Flight Operations
  • Microsoft-Edge-browser-gains-Copilot-Mode-Integrated-AI-naviagtes-searches-and-soon-shops-for-you
    Edge Gets New Copilot Mode Feature Making it an AI Browser
  • TikTok
    TikTok Launches In-App Travel Booking Service…
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • 566ea8be2c378c1e5a941e96023c993b
    PayPal Integrates Hotel Reservations Into Its App…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Research/How to do it Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: airlinecyber securityflightsresearcherssecurity
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Samsung Memory Warning Shows AI Chip Shortage May Last Into 2028 August 1, 2026
  • Siri AI Paywall Would Make Apple Intelligence A Services Business July 31, 2026
  • Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA July 31, 2026
  • Snapchat Stops Paying Fully AI-Generated Spotlight Videos As AI Slop Spreads July 31, 2026
  • Anthropic Says Claude Models Breached Real Systems During Cyber Tests July 31, 2026
  • DeepSeek V4 Flash API Raises The Pressure In The AI Agent Price War July 31, 2026
  • MTN Nigeria Fintech Revenue Slump Shows Airtime Lending Risk July 31, 2026
  • Google Earth AI Image Tool Shows How Fake Satellite Proof Could Spread July 31, 2026
  • Lesotho Launches National CSIRT As Cybersecurity Becomes Core Digital Infrastructure July 31, 2026
  • Gabon Data Centre Push Shows Africa Digital Sovereignty Is Becoming Infrastructure July 31, 2026
  • Inforcer Raises $50M As AI Turns Microsoft 365 Security Into An MSP Problem July 31, 2026
  • Rwanda 3G Shutdown Shows Africa Mobile Money Needs A Careful 4G Migration July 31, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.