Skip to main content
  1. Home
  2. Computing
  3. News

Report says hackers have easy access to flight bookings due to legacy systems

Add as a preferred source on Google

Your flight itinerary for your next trip may be hacked. According to new research from SR Labs, the legacy systems for managing travel bookings are terribly insecure.

At the recent Chaos Communication Congress, a cybersecurity conference in Germany, two researchers from SR Labs showed how the three major global distribution systems (GDS) are not using secure authentication. GDS is a system used for managing travel reservations where data is shared among travel agencies, airlines, and the passengers. The top three GDS providers in the field are Sabre, Amadeus, and Travelport.

Recommended Videos

Researchers Karsten Nohl and Nemanja Nikodijevic claimed that malicious actors could infiltrate these booking systems to alter passenger information and even cancel bookings. Most worryingly, the researchers said that they didn’t need much effort to do it, just the passenger’s last name and the six-digit Passenger Name Record (PNR).

The main problem? The GDS systems simply haven’t been updated. SR Labs claims that many of the legacy systems are failing to properly authenticate passengers beyond the PNR number. To add insult to injury, this PNR number is frequently shared in customer emails and can even in some cases be found printed on your luggage tags.

“While the rest of the Internet is debating which second and third factors to use, GDSs do not offer a first authentication factor,” said SR Labs in its report. “Instead, the booking code (aka PNR Locator, a six-digit alphanumeric string such as 8EI29V) is used to access and change travelers’ information.”

Accessing a traveler’s account would allow a hacker to not only mess around with their flight arrangement but potentially obtain payment data or further information to carrying out phishing attacks.

“Global booking systems have pioneered many technologies including cloud computing. Now is the time to add security best practices that other cloud users have long taken for granted,” said SR Labs. “In the short-term, all websites that allow access to traveler records should require proper brute-force protection in the form of Captchas and retry limits per IP address.”

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
This experiment shows how easy it is to poison an open-weight AI model for under $100
This research raises new doubts about trusting open weight AI models.
Computer, Electronics, Laptop

Open-weight AI models have been having a moment lately. Just this month, Moonshot's massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

Read more
Asus’ powerful new gaming laptop with a 240Hz Mini LED display makes its global debut
The 2026 ROG Strix G18 pairs up to RTX 5080 graphics with an Intel Core Ultra 9 290HX Plus CPU
ROG Strix G18 (2026) laptop

Asus has started rolling out the 2026 ROG Strix G18 globally, and the easiest way to describe it is as a slightly toned-down version of the ridiculous ROG Strix Scar 18. It keeps the same 24-core Intel Core Ultra 9 290HX Plus processor but tops out at an Nvidia GeForce RTX 5080 Laptop GPU instead of the Scar’s RTX 5090. (via Notebookcheck)

The Mini LED model gets the best balance

Read more
Every app on my phone has decided I need AI, and none of them bothered to ask
AI assistants are invading everything from photo libraries to messaging apps, and dismissing them only seems to guarantee they’ll return later.
Electronics, Phone, Mobile Phone

My wife doesn’t use AI very much. She isn’t philosophically opposed to it, nor is she waiting for the machines to overthrow civilization. She simply opens Google Photos because she wants to look at her photos.

Lately, however, the app keeps greeting her with invitations to try its AI tools. Google would very much like her to search her library conversationally, generate something new, or ask Gemini to edit a photo. She dismisses the prompt, gets on with her life, and eventually meets it again.

Read more