A security flaw in United Airlines’ website may have exposed ticket information for customers who requested a refund, according to a new report from TechCrunch.
The bug caused the website to not validate a user’s last name when checking their refund status. That made it possible to access other travelers’ refund information simply by changing the ticket number, TechCrunch reported.
Like many airlines, United’s website allows users to check their refund status by entering their ticket number and last name. It was not immediately clear whether another user’s information could be viewed without knowing their full ticket number.
IT security expert Oliver Linow discovered the bug and told TechCrunch that the security hole allowed him to see traveler names, payment type, currency used, and the refund amount. It was not clear whether any more sensitive information was visible.
Linow said that he reported the bug to United in July, and that it took the airline more than a month to fix it. He tweeted that he estimates that 100,000 user records were visible, possibly more.
Companies doing business in the European Union are subject to steep fines for failing to protect user privacy — it was not clear whether the bug affected European versions of United’s site, nor whether the bug was something that could subject United to penalties.
A spokesperson for United told Business Insider that the airline was looking into the report, but that he did not believe that any sensitive information was visible.
Airlines have been inundated with refund requests during the coronavirus pandemic as travelers cancel preexisting plans due to border closures, quarantine requirements, or safety concerns.
However, airlines have been slow to issue refunds as they work to manage cash flow during the crisis, prompting the Department of Transportation to warn airlines about complying with cancellation rules.