Huge OneFly data breach sees traveler IDs and payment details leaked


  • OneFly leaked thousands of sensitive customer records via an unsecured Elasticsearch instance
  • Data included names, IDs, flight details, full credit card details and JWT tokens
  • Cybernews encourages access control, refined logging and IP whitelisting to mitigate risks

Travel technology and flight content company OneFly has apparently leaked thousands of sensitive customer records, including unredacted payment information, online.

Security researchers from Cyber ​​news said they recently discovered “thousands of records” leaking from nine internal Java Spring applications in real-time through an Elasticsearch instance.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top