Flightradar24, one of the largest flight tracking services that shows the real-time location of planes on a map, has suffered a massive breach that may have leaked emails and encrypted passwords from the service's 230,000 users.

Without disclosing any details about the breach, the company began sending out emails to its users earlier this week asking them to change their passwords. Flightradar24’s lackluster announcement about the issue left many users confused, as there had been no official announcement at the time. The emails the company sent asking users to change their passwords contained password reset links, which users thought were suspicious, thinking they were some kind of phishing attempt.
However, statements were later made on Twitter and the forum confirming the breach and that the password reset links were genuine. Flightradar24 also assured users that no personal or credit card information was leaked.
Finally, the announcement states that all the leaked passwords were encrypted, but it does not mention which hashing algorithm, or if there was a second layer of encryption. To protect the accounts, Flightradar24 has deactivated the previous passwords and access is now only possible by using the password reset link. It is also recommended to change the passwords from other online services in case the same email and password are used.
