They found eight companies that don't encrypt airline check-in links. These were: Southwest, Air France, KLM, Vueling, Jetstar, Thomas Cook, Transavia and Air Europa.
In their report, they stated: "Our threat researchers discovered that these airlines sent unencrypted check-in links to passengers." They also went on to say: "Upon clicking these unencrypted links, a passenger is directed to a site where they are logging in automatically to the check-in for their flight, and in some cases, they can then make certain changes to their booking and print off the boarding pass."
The hacker could be able to view a lot of personal data associated with the booking including name and frequent traveller number. With this data, the hacker can access the personal identifiable information or (PII). This data includes email, name, document number, and flight numbers.
A spokesperson for Thomas Cook Airlines stated: "We have looked into the questions raised and have taken immediate action to further increase the security of our customer data."
Transavia stated that their IT teams are working to further enhance security on the link sent to customers as part of the check-in process.