✓ Connection Protected ISP: Anthropic, PBC (216.73.216.196)

OneFly Data Breach: 1000s of IDs & Credit Cards Leaked

A data breach at OneFly, a B2B travel service, has exposed thousands of sensitive records including full credit card numbers, ID documents, and flight details.

OneFly Data Breach

Security researchers discovered the leak through an unsecured Elasticsearch instance connected to internal applications. The exposed data was first spotted in late October 2025, with entries dating back to October 1st.

OneFly operates as a middleman between airlines and online travel agencies. Most travelers have likely never heard of this company, yet their personal information may have passed through its systems.

How the OneFly Data Breach Happened

The exposed Elasticsearch instance was logging sensitive information in real time without proper access controls. Approximately 10,000 ID records and 6,000 payment cards were found sitting in the open.

Leaked Customer Data
Leaked Customer Data (Source: Cybernews)

The leaked data includes:

  • Full credit card numbers
  • Passenger names and dates of birth
  • ID document details
  • Flight numbers, dates, and destination airports
  • Internal authentication tokens (JWT)

Beyond personal and financial records, the exposed authentication tokens could allow attackers to impersonate internal users and dig deeper into company systems.

TROYPOINT Tip: Protect your identity and personal info from a data breach by using Aura Identity Theft Protection which is TROYPOINT’s recommended identity theft protection.

Aura Identity Theft Protection Review

 
Your Connection is Exposed

Hide Your Digital Fingerprint

IP Address 216.73.216.196
Location Columbus, Ohio
ISP Anthropic, PBC
Secure My Connection Now
Limited Time: 85% Off + 3 Months FREE
 

As of this writing, OneFly has made no public statement about the breach. The company has not acknowledged the incident on its website or through any official channels.

OneFly Website
OneFly Website

Anyone who has booked flights through an online travel agency should monitor credit card statements closely and watch for phishing emails that reference specific flight details. Placing a fraud alert with a major credit bureau is also a smart move.

Final Thoughts

This breach is a reminder that your personal data often passes through companies you’ve never heard of. OneFly’s silence makes the situation worse, as affected travelers deserve to know their information was left unprotected.

Until companies like OneFly take data security seriously, consumers need to stay proactive about protecting themselves online and monitoring reports.

For more details on this story, refer to the report from Cybernews.

We want to know your thoughts. What do you think about this story? Let us know in the comment section below!

Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.

This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.

Leave a Comment

Your email address will not be published. Required fields are marked *

SURFSHARK VPN
ONLY $.07/DAY!

X
TROYPOINT Last Chance for VPN