United Airlines Awards Hackers Millions of Miles for Revealing Risks

Advertisement
By Reuters | Updated: 16 July 2015 13:42 IST
United Continental Holdings Inc has awarded millions of frequent flier miles to hackers who have uncovered gaps in the carrier's web security, in a first for the U.S. airline industry.

United confirmed with Reuters that it has paid out two awards worth 1 million miles each, worth dozens of free domestic flights on the airline. United did not confirm tweets from individuals who say they have been paid smaller awards as well.

The Chicago-based carrier has hoped to trailblaze in the area of airline web security by offering "bug bounties" for uncovering cyber-risks. Through the program, researchers flag problems before malicious hackers can exploit them. The cost can be less than hiring outside consultancies.

Advertisement

Three of United's competitors declined to comment on bug bounty programs. A fourth was not immediately available for comment.

Trade group Airlines for America said in a statement that all U.S. carriers conduct tests to make sure their systems are secure.

Advertisement

United unveiled the approach in May just weeks before technological glitches grounded its entire fleet twice, underscoring the risks that airlines face. One incident locked the airline out of its reservations system, preventing customers from checking in, and another zapped functionality of the software United needed to dispatch its flight plan.

"We believe that this program will further bolster our security and allow us to continue to provide excellent service," United said on its website, declining additional comment.

Advertisement

Jordan Wiens, a researcher focused on cyber-vulnerabilities, tweeted last week that he received United's top reward of 1 million miles for exposing a flaw that could have allowed hackers to seize control of one of the airline's websites.

"It's really interesting that United did what they did," he said in an interview. "There actually aren't that many companies in any industry outside of technology that do bug bounties."

Advertisement

Wiens said it was normal for large companies such as United to have bugs in their websites.

Terms of the agreement prohibit Wiens from disclosing the bug he discovered. The terms also required that Wiens reveal the supposed problem to United without trying to exploit it, meaning he does not know how much information he could have accessed or manipulated.

Beyond the bounty, United said it tests systems internally and engages cyber-security firms to keep its websites secure.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 Ultra, Vivo X300 FE Confirmed to Launch in India Soon
  2. Honor 600 Series' Chipset and Battery Details Revealed Ahead of Global Debut
  3. OTT Releases This Week (April 13 - April 19): Toaster, Matka King, Assi, and More
  4. Oppo Find X9s Pro Specifications Tipped Again Ahead of April 21 Launch
  5. DJI Osmo Pocket 4 Debuts With 1-inch CMOS Sensor, Improved Stabilisation
  6. Canva's Upgraded AI Suite Brings Agentic Capabilities to Complete Design Tasks
  7. Samsung Galaxy A27 Renders Hint at This Notable Change to Its Display
  1. Scientists Just Created the Largest 3D Map of the Universe Ever to Study Dark Energy
  2. Honor 600 Pro and Honor 600 Key Specifications, Features Revealed via Official Listing
  3. Ethereum NFT Platform Shuts Down After Blacklove Sale Falls Through
  4. Vivo X300 FE Storage Options Leaked Alongside Live Image With Telephoto Extender Kit
  5. Indian Smartphone Shipments Dropped to Six-Year Low in Q1 2026 as Vivo Topped Market, Nothing Led Growth: Counterpoint
  6. Canva Introduces Canva AI 2.0, Brings Agentic Capabilities and Memory to Perform Design Tasks
  7. MediaTek Dimensity 9600 Pro Leak Suggests 5GHz Clock Speed, High Benchmark Scores
  8. Oppo Find X9s Pro Key Specifications Surface Online as Launch Date Draws Closer
  9. Russian-Based Crypto Exchange Grinex Halts Operation After $14 Million Hack
  10. Assassin's Creed: Black Flag Resynced Will Reportedly Release in July, Reveal Set for Next Week
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.