
That barcode printed at the bottom of every boarding pass looks like meaningless clutter. In reality, it's a compact file packed with personal information, far more than the seat number and flight time most people assume it contains.
Security researcher Brian Krebs first exposed this in detail after a reader noticed a friend had posted a boarding pass photo on Facebook. Using a free barcode reader found online, that single photo was enough to pull the passenger's full name, frequent flyer number, and record locator, the unique code tied to their entire airline account.
That record locator turned out to be the real problem. With it, the researcher could log into the airline's system and view the passenger's phone number, upcoming flights, and additional personal account details, all from information hiding inside a barcode nobody thinks twice about.
It gets more serious than trip details. Security researcher Michal Špaček demonstrated at a cybersecurity conference that decoding a friend's boarding pass photo gave him access to that friend's passport number, citizenship, and date of birth. None of that information should have been reachable from a casual social media post.
Once inside an account, the access isn't just read-only. Reports have shown that someone holding this data could change seat assignments, cancel upcoming flights, or reset the account's security PIN, all without ever needing a password.
Airlines pack this much detail into the barcode for a practical reason. It allows any airline representative to scan a pass and instantly pull up a traveler's full itinerary and contact information if something goes wrong at the gate or counter. The convenience for staff comes at the cost of exposure for passengers.
The fix is almost embarrassingly simple. Security experts recommend shredding printed boarding passes after a flight and never posting a photo of one online, since the barcode alone, with no other information needed, has already proven to be enough.














