Frontier Airlines site leaks all personal info with just a glance at a boarding pass, researcher claims — booking number and last name nets you every passenger's personal info, including address, passport, TSA PreCheck, and most credit card info
Security researcher Bob reveals Frontier Airlines exposed passenger passport data, credit card info, and TSA PreCheck numbers through a simple API flaw — just a boarding pass code and last name.

Frontier Airlines Boarding Pass Vulnerability Exposes Passenger Data
A security researcher identified as "Bob" has publicly disclosed multiple critical vulnerabilities in Frontier Airlines' website and mobile API that allowed anyone with access to a boarding pass to retrieve full personal information for every passenger on a flight. The findings, published on the researcher's blog after a 105-day disclosure window, reveal that sensitive data including passport numbers, home addresses, credit card details, and TSA PreCheck codes were accessible with just a booking confirmation number (PNR) and a last name — two pieces of information printed on every boarding pass.
The Core Vulnerability: An API That Gives Away Everything
According to the researcher, Frontier's mobile application API endpoint returns the entire raw internal booking object when provided with a valid PNR and last name — requiring no additional authentication. The endpoint, accessible to anyone with a boarding pass in hand (or a photo of one), returns a startling amount of data:
Full home address (street, city, state, zip code), phone number, and email address; full date of birth for adults and minors; complete passport data including passport number, issuing country, and expiration date; the passenger's Known Traveler Number (KTN) used for TSA PreCheck; Frontier Miles loyalty program details; credit card information including the BIN (first six digits), last four digits, expiration date, cardholder name, and billing IP address; full payment history with authorization codes; internal system comments revealing every SMS and email notification sent.
"The website masks passport numbers as 'XXXX' — the API returns the full number," Bob wrote in the disclosure. "No filtering. No masking. The complete internal booking object, dumped straight to the client."
Credit Card Data: 10 of 16 Digits Exposed
The credit card exposure is particularly concerning. With the BIN (first six digits) and the last four digits known, and the 16th digit being a deterministic Luhn check digit, only five digits in the middle remain unknown — roughly 100,000 possible combinations. Combined with the cardholder name and expiration date, this represents a significant card-not-present fraud risk. The researcher noted that any PCI-DSS qualified assessor would rate this exposure as critical, and that it constitutes a reportable cardholder data exposure event under PCI-DSS 12.10.1.
Website Source Code Leaks
The vulnerabilities were not limited to the mobile API. The "Manage My Booking" page on Frontier's website displayed passenger email addresses and phone numbers as masked on-screen, but the full unmasked data was readily visible in the HTML source code. Despite Frontier's attempts to fix this issue, the "fix" actually made things worse — replacing the original leaks with new ones that exposed even more data, including phone numbers that were previously hidden.
The "Passengers/Edit" page in the booking management flow went even further, displaying all personal information in unmasked form fields: full names, email addresses, phone numbers, dates of birth, Known Traveler Numbers, and passport data. A server-rendered JSON blob embedded in the HTML source contained the full unmasked passport numbers.
TSA PreCheck Codes at Risk
Perhaps most alarmingly, the API exposed Known Traveler Numbers — the codes that grant passengers TSA PreCheck access. Per TSA handling guidance, these numbers should not be exposed to client-side rendered pages at all. An attacker with someone's KTN could potentially use it fraudulently, bypassing standard security screening at airports.
The researcher demonstrated the attack chain by finding a real Frontier boarding pass posted publicly on X (formerly Twitter). Even when the poster had redacted their name and confirmation code, the IATA-standard BCBP barcode remained visible, containing the full PNR and passenger name in machine-readable format.
A Frustrating Disclosure Timeline
Bob first reported the vulnerabilities to Frontier Airlines on March 3, 2026, following up on March 9 with additional findings including a PNR enumeration endpoint — one that returned booking data for any valid PNR with no last name required at all, making it possible to brute-force booking codes and access passenger data with zero initial information.
Frontier fixed the PNR enumeration vulnerability — the one requiring no last name at all — and sent Bob a model airplane as thanks. However, the company did not address the more critical vulnerabilities that continued to expose full passenger PII through the mobile API and website. Despite repeated follow-ups and a 30-day disclosure deadline set for June 12, the critical vulnerabilities remained live at the time of public disclosure on June 16.
"They fixed the easiest vulnerability and left the ones that actually leak passenger PII wide open," Bob wrote. "That's like fixing a broken window on a house that has no walls."
What This Means for Passengers
As of the disclosure date, the critical vulnerabilities remain live on Frontier's systems. Anyone who has flown Frontier Airlines and whose boarding pass has been photographed, posted on social media, discarded at an airport, or otherwise accessed by a third party could have had their personal information compromised. The researcher urged Frontier to take the vulnerabilities seriously, stating that the airline's passengers "deserve better."
Affected passengers should monitor their credit reports for fraudulent activity and consider placing a fraud alert on their credit files. Frontier Airlines has not yet issued a public statement regarding the disclosure.


