Huge OneFly data breach leaks traveler IDs, payment details


  • OneFly leaked thousands of sensitive customer records via insecure Elasticsearch instance
  • The data included names, IDs, flight details, full credit card information and JWT tokens.
  • Cybernews recommends access controls, fine-grained logging and IP whitelisting to mitigate risks

Travel technology and flight content company OneFly has apparently leaked thousands of sensitive customer records online, including unedited payment information.

Security researchers from Cybernews said they recently discovered “thousands of records” leaking in real time from nine internal Java Spring applications, via an Elasticsearch instance.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top