Airline Apps Could Have More Information Than You Realize

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Investigation into Sensitive Permissions of Popular Airline Apps: Cybernews Research

Cybernews research has uncovered concerning findings about popular airline apps and their access to sensitive data on travelers’ devices. With the increasing reliance on airline apps for check-ins, ticketing, and booking services, the potential privacy risks and cybersecurity threats are becoming more apparent.

Recent incidents, such as the ransomware attack on AirAsia in 2022, where data of over five million passengers and employees was stolen, highlight the vulnerabilities in airline app security. The National Cyber Security Agency in Malaysia is currently investigating another breach claim on AirAsia by a threat actor.

To shed light on the data collection practices of airline apps, Cybernews conducted an investigation into 14 popular aviation apps. The research revealed that many of these apps have access to sensitive information on users’ devices, including location, camera, storage, phone state, microphone, contacts, accounts, messages, and calls.

While some airlines disclosed the data they collect and the reasons for it, others did not provide clear information on their data collection practices. This lack of transparency raises concerns about user privacy and data security.

Cybernews advises users to review app permissions carefully before granting access and to be cautious about apps that request unnecessary permissions. By staying informed and vigilant, users can protect their data and ensure a safer digital experience while using airline apps.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Malicious Content Discovered on ‘third-party.com’ Domain Used in Over 1,700 Repositories

The domain "third-party.com," typically used as a documentation placeholder, has been identified as serving a ClickFix lure targeting Windows users while presenting a benign...

New MacSync Version Targets Crypto Enthusiasts with Advanced Infection Techniques

The emergence of the MacSync malware family marks a significant evolution in the landscape of cyber threats targeting macOS users, particularly those involved in...

Astrana Health Reports Data Breach Following Social Engineering Attack on Employees

Astrana Health has reported a data breach involving the theft of private and confidential information from its servers, following a social engineering attack that...

CloudSEK Addresses Escalating AI-Driven Cyber Risks in the Middle East

CloudSEK Tackles Rising AI-Driven Cyber Risks in the Middle East Cyber threats in the Middle East are escalating, with state-sponsored groups, ideologically motivated actors, and...