Get Updates
Get notified of breaking news, exclusive insights, and must-see stories!

Bengaluru techie 'hacks' IndiGo website to find lost luggage, airline says ‘at no point…’

New Delhi, Mar 31: Airports can be very harrowing even for seasoned travellers. There are so many things that one needs to look out for-tickets, identity cards, boarding passes, cell-phone, and of course luggage. And that sinking feeling you get in your stomach when you don't see your luggage at your destination is the worst nightmare at airports.

Bengaluru techie hacks IndiGo website to find lost luggage, airline says ‘at no point…’

An IndiGo passenger has gone viral after he claimed to find a "vulnerability" in the airline's website using which he was able to find the phone number of a co-passenger with whom his bag was mistakenly swapped.

Nandan Kumar, whose Twitter bio describes him as a software engineer, who was travelling from Patna to Bangalore on an IndiGo flight, had his luggage mistakenly picked up by a co-passenger and the incident prompted Kumar to put his skills to best use to find his lost luggage by hacking into the airline's website.

Kumar took to Twitter and shared the story of how he retrieved his luggage. He also narrated the entire incident and told the IndiGo airlines about the loopholes in their website.

"Hey IndiGo. Want to hear a story? And at the end of it I will tell you hole (technical vulnerability )in your system?" is how Nadan starts the story.

Kumar wrote, "So, I travelled from PAT - BLR from indigo(sic) 6E-185 yesterday. And my bag got exchanged with another passenger. Honest mistake from both our ends. As the bags were exactly the same with some minor differences."

Kumar contacted IndiGo's customer service which tried to contact the other passenger "but all in vain."

Kumar then decided to take the matter in his own hands and this is where the story gets interesting.

"I pressed the F12 button on my computer keyboard and opened the developer console on the IndiGo website and started the whole checkin flow with network log record on," he wrote.

"And there in one of the network responses was the phone number and email I'd of my co-passenger. Ah this was my low-key hacker moment and the ray of hope. I made note of the details and decided to call the person and try to get the bags swapped," the software developer added.

Kumar's effort yielded results and both the passengers swapped bags.

Kumar highlighted two problems with IndiGo here: one, their poor customer care service; and two, the data leak.

IndiGo took notice of Nadan's story and responded with an apology for the inconvenience and assured that the website has no security lapses.

"Any passenger can retrieve their booking details using PNR, last name, contact number, or email address from the website. This is the norm practiced across all airline systems globally," the airline stated.

Notifications
Settings
Clear Notifications
Notifications
Use the toggle to switch on notifications
  • Block for 8 hours
  • Block for 12 hours
  • Block for 24 hours
  • Don't block
Gender
Select your Gender
  • Male
  • Female
  • Others
Age
Select your Age Range
  • Under 18
  • 18 to 25
  • 26 to 35
  • 36 to 45
  • 45 to 55
  • 55+