Skip to content
Back to Blog
low severity August 13, 2024 · 4 min read

FlightAware Data Breach Notice (Oregon Attorney General)

If you received a notice from FlightAware, here’s what the filing says was exposed, and what to do about it.

FlightAware notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on August 13, 2024. The filing puts the incident itself on January 01, 2021.

FlightAware Data Breach Notice (Oregon Attorney General)

The personal information of up to 2 million people was exposed in a FlightAware breach that occurred on January 1, 2021. The company filed its notification with Oregon authorities on August 13, 2024 — an interval of 1,320 days, or roughly 43 months.

Names and addresses from 2021 remain useful to identity thieves today

If you received a notification letter from FlightAware, your name together with address and other personal information listed in the filing may still be circulating. These details do not expire. Criminals continue to combine them with information obtained elsewhere to build convincing profiles for account takeover attempts, tax fraud, or targeted phishing years after the original incident.

The filing lists only personal information as exposed. No passwords, financial account numbers, Social Security numbers, driver’s license numbers, passport numbers, or medical details appear in the categories named by the record. That absence is meaningful: the letter you received will confirm exactly which details applied to you, but the official notification does not indicate that permanent government identifiers or login credentials were compromised.

What the long delay between incident and notification actually means

The breach happened more than three and a half years before the Oregon filing. Notification timelines vary by state law and by the time required to complete an investigation, so the 43-month gap cannot be labelled negligent on the public record alone. What matters to you is that the personal information taken in January 2021 has had ample time to move through criminal markets and be combined with newer datasets.

FlightAware is required to notify affected individuals directly, usually by mail to the last known address on file from the time of the incident. If you have not received such a letter, it is likely your information was not included. However, anyone who has moved since January 1, 2021 should contact FlightAware directly to confirm whether their records were part of the exposed group.

The difference between what can and cannot be replaced

Because the exposed category is limited to personal information, the immediate risk centers on identity-related fraud rather than direct account compromise. A name and address alone rarely unlock financial accounts, but they lower the bar for someone attempting to impersonate you when paired with data from other breaches.

No passwords were exposed, so there is no need to change your FlightAware password because of this incident. The record contains no indication that login credentials were involved. Your account itself is not placed at additional risk by this particular filing.

How criminals typically use this kind of personal information

Names and addresses remain valuable for:

  • Creating synthetic identities when combined with stolen Social Security numbers from unrelated breaches
  • Crafting phishing emails or text messages that appear to come from legitimate companies you have done business with
  • Filing fraudulent tax returns or unemployment claims in jurisdictions that use address history for verification

The passage of more than three years does not reduce this value. On the contrary, the data has had time to be tested, packaged, and resold multiple times.

What you can still control

Place a freeze on your credit reports at the three major bureaus. This remains the single most effective step against new-account fraud even when Social Security numbers are not confirmed exposed. It is free, reversible, and stops most lenders from opening accounts without your explicit permission.

Review your annual tax transcripts from the IRS and your state revenue department. Look for returns you did not file. Early detection is the only practical defense against tax-related identity theft.

Be especially wary of unsolicited contact that references FlightAware, air travel, or any details that could plausibly come from 2021 customer records. Treat any such message as suspicious regardless of how professional it appears.

Consider whether you need to update your address history with government agencies and financial institutions if you have moved since the incident date. Outdated contact information increases the chance that legitimate warnings never reach you.

Finally, monitor existing accounts for unusual activity, but do not treat every login attempt as evidence of this breach. The absence of credential exposure in the filing means the most common vector — stolen passwords — is not present here.

The record is narrow by design. It tells us what category of information was involved and how many Oregon residents were notified. It does not disclose the root cause, whether data was copied or simply viewed, or the precise system affected. Those details remain unknown to the public. What is known is that personal information from January 2021 is now on record as exposed, and the people named in the filing have had more than three years of potential exposure time.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed August 13, 2024
Last reviewed July 22, 2026
Affected 2000000
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email