Theregister iconTheregisterSep 9, 2026

Security boffin claims airport group left API keys in client-side JavaScript for four years

Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion

Security boffin claims airport group left API keys in client-side JavaScript for four years

Share this story

Send the public story page.

Useful takeaways from this story.

Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app