You’ve just checked in for your dream vacation. The excitement is real, so naturally you snap a photo of your boarding pass and share it on Instagram with the caption ‘See you in paradise!’ Thousands of travelers do this every single day, thinking it’s harmless. It feels like sharing a movie ticket stub or a restaurant receipt. Yet security experts are practically screaming at us to stop, and the reasons why will probably make you delete that post immediately.
That little piece of paper or digital ticket you’re holding contains way more personal information than most people realize. We’re talking about data that goes far beyond your name and destination. Hackers and identity thieves have figured out clever ways to exploit boarding passes, and the consequences range from stolen frequent flyer miles to full-blown identity theft. Some victims have even had their entire trips hijacked while they were mid-flight. The scary part is how easy it is for criminals to pull this off using just one photo you posted online. Let’s dive into exactly what dangers are hiding in that innocent-looking barcode.
That Innocent Barcode Holds More Than You Think

Picture this. You’re at the airport, coffee in hand, boarding pass ready for that dream vacation. The excitement is real, and you want to share it with the world. So you snap a quick photo of your boarding pass, maybe add a caption like “Off to paradise!” and hit post on Instagram or Facebook. Seems harmless enough, right? Wrong. That tiny piece of paper or digital pass you just shared contains a goldmine of personal information that cybercriminals can exploit in ways that might shock you.
A quick search of #boardingpass on Instagram will show you thousands of recent posts by users displaying their boarding passes with completely visible barcodes. When searching #boardingpass on social media, it yielded approximately 95K results. Most of these people have no idea they’ve just handed over keys to their personal data. Let me walk you through what’s really at stake here, and trust me, after reading this, you’ll think twice before sharing any travel documents online.
The Hidden Data Lurking in Your Barcode

Two-dimensional barcodes and QR codes can hold a great deal of information, and the codes printed on airline boarding passes may allow someone to discover more about you, your future travel plans, and your frequent flyer account. Think about it for a second. That barcode isn’t just there to get you through security. It’s a compressed storage unit packed with details you’d normally keep private.
Boarding passes, whether paper or digital, contain more than just the traveler’s name and flight number. They include numeric codes, such as the Passenger Name Record (PNR) and other sensitive information, which, with a bit of online investigation, can reveal much more about the traveler. Your boarding pass contains a lot of information, including your full name, flight route, and frequent flier or airline loyalty account number. That number is often associated with other details, such as your home address, phone number, and airline points.
Here’s the thing that really gets me. The barcode will also reveal one key piece of information: The passenger’s full airline account number. Sometimes, additional details belonging to the account, such as email address, phone number, and more, will also be available. All anyone needs to see this hidden information is a barcode scanner, the same kind that scans items at the grocery store. Barcode scanners can be easily found on various websites and in app stores, often for free. Literally anyone with a smartphone can decode your boarding pass in seconds.
Your Frequent Flyer Miles Are at Serious Risk

Let’s talk about something that hits close to home for frequent travelers. Those loyalty points you’ve been accumulating for years? They’re vulnerable. With access to the full frequent flier account number, a scammer can then get “secret question” information like mothers’ maiden names or high school mascots from social media to log into the account. From there, the criminal can wreak havoc by changing or canceling future reservations, stealing frequent flier points, and more.
According to a Forbes report, once transferred out of your account, your frequent flyer points are virtually impossible to recover. That’s the brutal truth. According to a report by Arkose Labs, frequent flier accounts are particularly vulnerable because airlines allocate most of their budget to aircraft operations, leaving only about 7% of their overall IT budgets for cybersecurity. The airlines simply aren’t investing enough in protecting your accounts.
Your frequent flyer number and loyalty program information are included on the boarding pass. This information can be used by hackers to access your rewards program account and steal your miles. I’ve heard stories from travelers who logged into their accounts months later only to discover their miles had vanished. By that point, it’s too late to do much about it.
Hackers Can Actually Change Your Flight Details

This one sounds like something out of a thriller movie, but it’s disturbingly real. Someone with access to a boarding pass barcode now had the ability to view all future flights tied to that frequent flyer account, change seats for the ticketed passengers, and even cancel any future flights. Imagine landing after a long-haul flight only to discover your return ticket has been cancelled by some stranger who found your posted boarding pass.
Once inside his friend’s account, a researcher saw he could cancel future flights and view or edit his friend’s passport number, citizenship, expiration date, and date of birth. The booking information and reference number, combined with your first and last name, are often sufficient for making changes to your itinerary. So if you want to avoid a prankster hacker canceling your flight ticket minutes before you board the plane, do not post the photo of your boarding pass on the internet.
In one recent high-profile case, a scammer used a photo of a traveler’s boarding pass to access their airline account and alter their return flight. That’s not theoretical. That actually happened to someone. The worst part? Most airline systems don’t require much more than your PNR code and last name to make changes.
The PNR Code Is Your Temporary Password to Everything

The six-digit booking code or PNR is essentially a temporary password issued by airlines that is then summarily printed on all luggage tags and inside all boarding pass barcodes. “You would imagine that if they treat it as a password equivalent, then they would keep it secret like a password,” Only, they don’t, but rather print it on everything you get from the airline. For instance, on every piece of luggage, you have your last name and the six-digit (PNR) code.
Think of the PNR as a master key. If someone gets this code and knows your last name, they can access the system to view details regarding your trip, including flights, ticket numbers, contact information, together with even special requests. Your reservation, in certain instances, may be able to be amended or canceled. The system’s main weakness is that no password is required to access PNR files, just the passenger’s last name and PNR code. This code only contains six characters, meaning hackers can repeatedly attack airline websites until they find the correct combination.
The booking code, a 6-digit alphanumeric string, is used to access and change travelers’ information without any proper authentication factor. A penetration tester has developed a tool that would allow an attacker to access a random individual’s flight information by using common last names and by brute-forcing the PNR. An attacker could also track a specific individual’s travels if they knew their last name and the airline they are using. The security infrastructure is shockingly outdated.
Social Engineering Attacks Become Child’s Play

Here’s where things get even more sinister. If the hacker isn’t successful at logging in using that information alone, all they need to do is a bit of social engineering. Armed with your boarding pass data, scammers can call you pretending to be the airline. They already have your flight details, your name, and your frequent flyer number. Everything checks out, so you trust them.
The information contained in the boarding pass could make it easier for an attacker to reset the PIN number used to secure a frequent flyer account. That information gets you past the early process of resetting an account PIN. After that, the site asks for the answer to a pre-selected secret question. The question might be “What is your Mother’s maiden name?” That information can often be gleaned by merely perusing someone’s social networking pages.
The combination of public social media profiles and boarding pass data creates a perfect storm for identity theft. Security experts say, “The real danger lies in how easily this information can be weaponized. With just a name and PNR, an attacker could log into an airline’s website and hijack an account or steal accumulated travel miles”. They can piece together your entire life from scattered digital breadcrumbs.
The Baggage Tag Scam You’ve Never Heard About

A Reddit post warns airline travelers of a new scam in which fraudsters steal baggage tags to make false claims of missing items at the baggage claim. Delta is “getting an influx of fraudulent claims” where scammers use the information from discarded airline baggage tags to claim “missing items” that aren’t theirs. Your discarded luggage tags contain the same PNR code as your boarding pass.
This form of identity theft is proving to be an issue for the airlines. “It is causing issues with reimbursing the real people if they submit a legitimate claim”. The scammers are filing fraudulent compensation claims using information from tags they find in airport trash bins. “As a former hotel employee, there have been a few instances of fraud using bag tags found at hotels, too,” according to online reports from 2025.
What You Should Actually Do With Your Boarding Pass

If you must print your boarding pass, keep it secured at all times and don’t leave it out where someone could quickly scan it or snap a quick pic. Once you’ve made it home, go ahead and shred it. Consider tossing the boarding pass into a document shredder instead of just throwing it in the trash. Paper shredders aren’t expensive, and they’re worth the investment.
Your safest bet for protecting your sensitive travel information is to avoid paper completely. Opt to receive your boarding pass digitally instead of printing it so no one can see or access the barcode. Digital passes on your phone are more secure because they’re not sitting in a seat pocket or trash can for anyone to grab. Using an electronic boarding pass eliminates the need to worry about where and how to discard a physical one. The digital pass has more security features, thanks to a combination of encryption, restricted access, and tighter integration with airline and airport systems.
Avoid posting pictures of your boarding pass, flight details, or baggage tags on social media platforms like Instagram, Twitter, or Facebook. Even a partial image can provide cybercriminals with the necessary details to breach your travel accounts. Once your trip is complete, make sure to securely dispose of your boarding pass. It’s really that simple. The five seconds of social media validation aren’t worth the potential nightmare of identity theft or account hijacking.
The bottom line is this. Your boarding pass is not a trophy to display. It’s a document containing sensitive personal information that should be protected like your credit card or passport. Every security expert agrees on this point. The technology exists to exploit these vulnerabilities, and criminals are absolutely using it. So next time you’re tempted to share that airport selfie with your boarding pass visible, remember everything you’ve just read. Your future self will thank you for keeping that barcode private. What precautions do you take with your travel documents? Have you ever thought twice about what information you’re sharing online?






