Frontier Airlines Sued Twice After Data Breach Hit 11,482 People—Ransomware Gang Claims Credit

Frontier Airlines is facing two class action suits after a data breach involving over 11,000 employees and customers.

A group calling itself Scattered Lapsus$ Hunters claims it stole a “treasure trove” of personal information and demanded a ransom. The Texas Attorney General’s breach database says the unauthorized access ran from May 12 through June 3 and was discovered June 18. It lists 11,482 people affected and says the data included names, addresses, Social Security numbers, driver’s-license and other government identification numbers, dates of birth and other information.

Frontier acknowledged the breach, says it brought in an outside cybersecurity firm, contacted law enforcement, and found no evidence of continuing access.

A Frontier employee filed a lawsuit Wednesday in Colorado federal court accusing Frontier of negligence, invasion of privacy and breach of fiduciary duty and seeks a class action representing everyone in the United States whose information was compromised. A passenger filed a separate proposed class action in Colorado on Monday.

While it’s not clear this is related, Frontier had just been contacted by a security researcher in March saying a confirmation number and last name (which are both printed on a boarding pass) could pull up passenger contact information, birth dates, passport details, Known Traveler Numbers, payment history and partial card information through Frontier’s website. They’re on notice about security flaws, but they say they fixed this specific issue.

Here’s the thing – as far as I can tell, other than ‘spending time researching the breach and changing passwords’ it’s not clear that either plaintiff was actually harmed. All our data is out there on the dark web already. Most of the time it lays dormant. There’s so much of it, and most of us aren’t worth bothering with. A federal lawsuit needs a concrete injury, not just the idea that one could happen later.

Frontier’s IT security may have been inadequate but the truth right now is that so is everyone’s. Leaving aside how much data is already out there, and much more sensitive data, frontier AI models seem almost impossible to defend against. I know the argument that if we accelerate access to the models that we’ll be able to use them to plug holes before they can be exploited, but most systems won’t be plugged fast enough.

About Gary Leff

Gary Leff is one of the foremost experts in the field of miles, points, and frequent business travel - a topic he has covered since 2002. Co-founder of frequent flyer community InsideFlyer.com, emcee of the Freddie Awards, and named one of the "World's Top Travel Experts" by Conde' Nast Traveler (2010-Present) Gary has been a guest on most major news media, profiled in several top print publications, and published broadly on the topic of consumer loyalty. More About Gary »

More articles by Gary Leff »

Comments

  1. Gary, your argument that “our data is already on the dark web” is a dangerous admission of corporate negligence, not a valid defense for a data breach. If we accept that faulty logic, we’re letting corporations abandon their duty to protect our privacy. Also, shifting blame to ‘AI’ for these breaches is another deflection; the burden should be on the corporation to implement systems they can actually secure; if they can’t secure the data, they shouldn’t be allowed to store it.

  2. Fire the employee that filed a suit. That should be the first thing done. Any employee that sues their employer shouldn’t be allowed to work for them.

  3. @Retired Gambler — My dude, it’s a *former* Frontier employee… Gary just didn’t include that. So, please, do not fear, the workers aren’t uniting or seize the means of anything, just yet… for the foreseeable future your precious, unregulated ‘corporate feudalism’ is still alive and well in the USA… phew! /s

  4. Almost as bad as the ransomware racket is the Class Action Lawsuit Racket. Federal law clearly says that the plaintiffs have to have actual injury to file a Federal lawsuit. These plaintiff aren’t even trying to claim actual injury. The lawyers who file theses lawsuits should be disbarred. They are doing nothing more than wasting the courts time for the purpose of extorting a settlement where the alleged” victims” will receive a few dollars and the lawyers make millions.

  5. @Steve — Ah, the ‘lawyers-bad’ trope. (We get it. They’re mercenaries. Yuck.) Still, that doesn’t diminish the failure by Frontier to protect their customer’s data.

  6. @1990- I don’t disagree. Frontier should be held accountable under the law whether it be regulatory or tort law. I will leave the regulatory part to the regulators. The tort law is very clear. In order to file a Federal Law suit there has to be actual damages not possible future damages. Lawyers know this but get away with and in many cases are enriched by filing these type of lawsuits anyway. Yes they are mercenaries but just like Frontier should be held accountable for their failure to safeguard data, there lawyers should be held accountable for filing lawsuits that under the law have no business being filed. At the very least they should be forced to pay defense costs for the defendants in these cases.

  7. Got a call from Cap1 asking if the monthly charge I pay every month to Google was authorized. Said yes. They said my card was compromised and they were shutting it down & sending new one. Would not tell me what was compromised by whom or how. Then got an email from Google telling I had 4 comprised passwords on 4 dormant accounts and I needed to change the passwords. Again no one tells you anything about what is going on. (ps many of these emails are also fake so don’t just click). The companies make us verify ourselves thirteen different ways with codes sent to other devices, security questions, etc. but the companies holding the data themselves are the biggest security threat/leak.

Leave a Reply

Your email address will not be published. Required fields are marked *