Akasa Air, India’s newest commercial airline, exposed the personal data of its customers that the company blamed on a technical configuration error.
According to security researcher Ashutosh Barot, the issue is found in the account registration process, leading to the exposure of personal details such as names, gender, email addresses, and phone numbers.
The bug was identified on August 7, 2022, the same day the low-cost airline commenced its operations in the country.
Barot stated that he found an HTTP request which gave his name, email, phone number, gender, etc. in JSON format. He immediately changed some parameters in the request and was able to see other user’s PII. He took around 30 minutes to find this issue.
The company upon receiving the report has stated that they have temporarily shut down parts of its system to incorporate additional security guardrails. It has also reported the incident to the Indian Computer Emergency Response Team (CERT-In).
Akasa Air emphasized that no travel-related information or payment details were left accessible and that there is no evidence the glitch was exploited in the wild.
The airline further clarified that it has directly notified affected all users of the incident, although the scale of the leak remains unclear. They also advised users to be conscious of possible phishing attempts.















Comments