Spread the love

As Aussies scramble to book that last-minute Bali escape or a cheeky New York detour before spring rolls in, the darker corners of the internet are teeming with something far less cheerful: leaked staff passwords from your favourite travel sites.

Yes, mate—while you’re punching in your credit card details to snag that elusive flight deal, there’s a good chance the booking platform’s staff haven’t even changed their password since the last major breach.

According to the latest deep dive by the Business Digital Index (BDI)—a report that should frankly be compulsory reading for every travel IT manager—the cybersecurity landscape of our beloved travel and tourism platforms leaves much to be desired.

During the height of the travel season, when booking engines are firing on all cylinders and raking in millions of transactions daily, BDI took a microscope to 20 of the world’s most visited travel-related websites. What they found wasn’t just troubling—it was, in some cases, downright negligent.

Old Breaches, New Blunders

Let’s get one thing straight. This isn’t about fresh cyberattacks. No, this is about old wounds that were never properly stitched up.

BDI’s analysis of leaked credential databases on the dark web revealed that staff from 18 out of 20 travel companies still have passwords from past breaches floating around like unclaimed baggage on a carousel.

And the real kicker? In half of those companies, some employees used the same password in multiple breaches. That’s not just lazy—it’s digital Russian roulette.

“These aren’t hypothetical risks. These are credentials sitting in public view on dark web marketplaces,” the report warns. “And the question is whether companies have done enough since the original breaches to prevent repeat vulnerabilities.”

Spoiler alert: Most haven’t.

Who’s Making the Grade?

BDI didn’t just sling accusations—they graded the platforms too, giving them scores out of 100 based on password hygiene, web application security, patching practices, email protection, and more.

Here’s where it gets spicy.

Only two out of the 20 companies earned an “A”:

  • Trip.com came out swinging with a top-tier score of 98/100, showing textbook security implementation and barely a wrinkle in their SSL setup.

  • Flightradar24, the plane-spotter’s favourite, followed closely with 96/100, bolstered by a clean employee breach record (just six leaked credentials).

And the worst of the worst?

  • Skyscanner takes home the wooden spoon with a shocking 55/100, thanks to nearly a thousand compromised credentials and 24 unpatched high-risk security holes.

  • Marriott International and Hilton—two of the globe’s hotel titans—each scored a limp 66/100, their staff credentials turning up in dark web bazaars like two-for-one happy hour deals.

  • Weather sites weren’t spared either. Germany’s Wetter.com, surprisingly one of the most visited global weather platforms, was slammed for having 15% of employees still reusing breached passwords.

Here’s a quick glance at how the class performed:

Rank Company Grade Score
1 Trip.com A 98
2 Flightradar24 A 96
D-F 66–74
20 Skyscanner F 55

(Full list available here)

Why This Should Matter To You

Now, you might be thinking: “So what if Sandra from Expedia’s HR team hasn’t changed her password since 2017?” Well, here’s the rub.

Compromised credentials don’t just lead to awkward email leaks—they open the door to full-blown attacks: data theft, ransomware, phishing campaigns. And when a hacker walks through that door with valid keys, the fallout hits consumers first.

In a digital age where trust and reputation are the currency of travel, such oversight is both astonishing and unforgivable.

As travellers, we expect our data to be guarded with the same diligence airlines use to lock their cockpit doors. Not left swinging on a rusty hinge.

A Call for Common Sense Security

The BDI report offers a sobering reminder: no matter how sleek the interface or how clever the loyalty program, the back end matters. Travel companies must treat cybersecurity with the same urgency as lost luggage and delayed flights.

“It’s not enough to recover from a breach. Prevention is where the real work lies,” says the report.

Perhaps it’s time more companies followed that old-fashioned wisdom: change your password, mate.

Further reading: Full report and scores available at BusinessDigitalIndex.com.

By Jason Smith

=======================================