FlightAware, Inc.
bd_5420b326bc910f52 · schema v1 · pii pii-v1
Full breach record for FlightAware, Inc. →FlightAware, Inc. disclosed a data security incident discovered on July 25, 2024, caused by a configuration error that potentially exposed personal information of account holders. The exposed data may include user IDs, passwords, email addresses, full names, billing/shipping addresses, IP addresses, social media accounts, telephone numbers, year of birth, last four digits of credit card numbers, aircraft ownership info, industry, title, pilot status, and account activity. Social Security Numbers may also have been exposed. The company remedied the error and is requiring password resets and offering two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1d12f0eec78a36ecOregon State AGfiled 2024-08-13Candidate
- bd_ecdaa81c1e52629eWashington State AGfiled 2024-08-13Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-590178
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 13, 2024
- Raw hash
- 5c1310f9e6d52b9d92286027e505219645568bd1601b3b12b71e1668aaf8701f
Reporting entity
- Name
- FlightAware, Inc.norm: flightaware
- Domain
- flightaware.com
Victim entity
- Name
- FlightAware, Inc.norm: flightaware
- Domain
- flightaware.com
Incident
- Discovered
- Jul 25, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTLOCATIONBEHAVIOREMPLOYMENT
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 19 days(19 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.