Huge OneFly data breach causes traveler IDs and payment details to be leaked



  • OneFly leaked thousands of sensitive customer records through an unsecured Elasticsearch instance
  • The data included names, IDs, flight details, complete credit card information, and JWT tokens.
  • Cybernews Urges Access Controls, Refined Logs and IP Whitelists to Mitigate Risks

Travel technology and flight content company OneFly has apparently leaked thousands of confidential customer records online, including unredacted payment information.

security researchers cyber news They said they recently discovered “thousands of logs” leaked from nine internal Java Spring applications in real time, via an Elasticsearch instance.



Leave a Comment

Your email address will not be published. Required fields are marked *