Menu
Browse

Cyber Incident Victim: Flightradar24

Date:

Jun 2018

Location:

Sweden

Summary

A flight-tracking service experienced a security breach compromising email addresses and hashed passwords for users registered prior to March 2016. The incident was confined to a single server, which was immediately deactivated upon detection. No personal information or payment data was affected, as the platform did not store such details. Affected subscribers received direct notifications prompting password resets, with some initially suspecting phishing attempts until company representatives verified the legitimacy of communications through official forums. The organization emphasized no evidence of broader data misuse but strongly advised impacted users to update credentials, particularly if reused across other services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In June 2018, Flightradar24 detected a security breach affecting users who registered accounts before March 16, 2016. The incident, identified in late June, involved unauthorized access to one server that stored email addresses and hashed passwords for a subset of older user accounts. The company promptly shut down the compromised server upon discovering the intrusion attempt. Flightradar24 notified impacted users via email, advising them to reset their passwords and warning against password reuse on other platforms. Some recipients initially suspected the notification was a phishing scam due to its inclusion of a password reset link, prompting company representatives to confirm the breach’s legitimacy through official forums. A staff member named Olga clarified that the breach was confined to a single server and emphasized there was no evidence of compromise to personal information beyond email addresses and hashed credentials.

Cyber Incident Image

The breach did not expose payment data, as Flightradar24 did not store such information. The company’s response focused on mitigating risks by instructing affected users to change their passwords immediately, particularly if they had reused credentials elsewhere. This precaution was highlighted as critical given the likelihood that aviation professionals—a key user group—might access sensitive industry systems with similar passwords. Flightradar24’s public communications stressed the limited scope of the incident but underscored the broader security implications of credential reuse. No further technical details about the attack vector or the identity of the threat actors were disclosed in the available information. The incident underscored operational risks associated with legacy user data and reinforced standard breach response protocols, including server isolation and user notification.

Sources
Sources available to members
1 source