---
title: "The TSA’s Entire No Fly List Appears to Have Just Leaked"
description: "A Swiss cybersecurity hacktivist has leaked the TSA's No-Fly List, a highly sensitive document, after discovering it on an unsecured server."
date: "2023-01-23"
modified: "2023-01-23"
authors:
  - name: "Victor Tangermann"
    job_title: "Senior Editor"
    link: "https://futurism.com/authors/victor"
url: "https://futurism.com/the-byte/hacktivist-leaks-tsa-entire-no-fly-list"
categories:
  - "Advanced Transport"
tags:
  - "air travel"
  - "cybersecurity"
  - "the digest"
  - "tsa"
---

# The TSA’s Entire No Fly List Appears to Have Just Leaked

![A Swiss cybersecurity hacktivist has leaked the TSA's No-Fly List, a highly sensitive document, after discovering it on an unsecured server.](<https://futurism.com/wp-content/uploads/2023/01/hacktivist-leaks-tsa-entire-no-fly-list.jpg>)
*\<em\>Image: Getty Images\</em\>*

## TSA Leak

A cybersecurity hacktivist appears to have leaked the Transportation Security Administration’s No Fly List, a highly sensitive document, after discovering it on an unsecured server, the [*Daily Dot* reports](<https://www.vice.com/en/article/93a4p5/us-no-fly-list-leaks-after-being-left-in-an-unsecured-airline-server>).

Unsurprisingly, the TSA is [now investigating](<https://abc17news.com/politics/national-politics/cnn-us-politics/2023/01/20/tsa-investigating-how-some-no-fly-list-data-was-exposed-on-internet/>) how the data was exposed.

It's an egregious lapse in cybersecurity protocols that has already outraged members of Congress, who "will be coming for answers," as representative Dan Bishop, a Republican congressman who serves on the House Homeland Security Committee, [put it](<https://twitter.com/RepDanBishop/status/1616892105758236673>).

"The entire US no-fly list — with 1.5 million+ entries — was found on an unsecured server by a Swiss hacker," Bishop [tweeted](<https://twitter.com/RepDanBishop/status/1616892105758236673>). "Besides the fact that the list is a civil liberties nightmare, how was this info so easily accessible?"

## NoFly.csv

The incident couldn't have come at a worse time. The last couple of months have been chaotic for the TSA. Earlier this month, for instance, a computer issue forced the Federal Aviation Administration (FAA) to [ground thousands of flights](<https://www.reuters.com/business/aerospace-defense/us-faa-says-flight-personnel-alert-system-not-processing-updates-after-outage-2023-01-11/>).

A text file simply named "NoFly.csv" was found on a server run by US airline CommuteAir — for practically anybody to discover and download, the *Daily Dot* reports.

The document includes the list of names and aliases of anybody barred from boarding an aircraft in the US, a subset of individuals on the Terrorist Screening Database.

Its existence has been challenged by many [privacy groups](<https://www.aclu.org/issues/national-security/grounded-life-no-fly-list>) and civil liberties advocates over the years.

The extensive list reportedly included a recently freed Russian arms dealer, suspected members of the Irish paramilitary organization IRA, and an eight-year-old child.

Many of the entries also "appeared to be of Arabic or Middle Eastern descent," according to the report.

"It’s just crazy to me how big that Terrorism Screening Database is and yet there is still very clear trends towards almost exclusively Arabic and Russian sounding names throughout the million entries," the hacker told the *Daily Dot*.

## Cybersecurity Incident

The document even included sensitive personal data of more than 900 CommuteAir employees, including passport numbers and addresses.

It's an embarrassing incident that goes to show just how vulnerable these databases are to being leaked to the general public.

And that's not to mention the fact that the TSA is a [fundamentally broken, unjust, and bloated organization](<https://www.theverge.com/c/23311333/tsa-history-airport-security-theater-homeland>) that does little to justify its own existence in the first place.

**READ MORE:** [EXCLUSIVE: U.S. airline accidentally exposes ‘No Fly List’ on unsecured server](<https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotected-server-commuteair/>) \[*Daily Dot*\]

**More on the TSA:** *[The FBI Says Apple’s New Encryption Is “Deeply Concerning”](<https://futurism.com/the-byte/fbi-apple-new-encryption-deeply-concerning>)*

## Author
I've been at Futurism since 2017, where my role has evolved to encompass design, writing, and increasingly editing. I've always been fascinated by space exploration and advanced transportation, which I've leaned into by interviewing luminaries in those fields while closely following the dimensions of policy and regulation that allow next-generation projects to succeed -- or, sometimes, to fail. I'm also keenly interested in the effects of generative AI on society, policies, and democratic institutions, as well as clean energy, physics and biology, and the vagaries of tech leadership. My work for Futurism has been cited by publications including Ars Technica, Gizmodo, PC Magazine, Jalopnik, Fox News, and the New York Post. I spent my childhood living in locations including Manila, the Philippines, and Geneva, Switzerland, attended McGill University, and now live in Toronto, Canada. Before Futurism I worked at AskMen and a small photography studio. In my free time, I'm an avid gardener, foodie, and craft beer lover, as well as a maker of artisanal hot pepper sauces. I have a magnificent dog named Freida.

### Author social links  
[Bluesky](<https://bsky.app/profile/vtanger.bsky.social>)