United Airlines will reward hackers with air miles
Bug bounty programme is first of its kind for US airline industry


United Airlines has set up a bug bounty programme, which rewards hackers with air miles, in a bid to beef up its cyber security standing.
With traditional bug bounty programmes, when hackers or researchers find a flaw, rather than exploiting it, they receive a monetary reward for reporting it.
United Airlines has opted for a different route. Instead of money, the firm is paying out air miles for bug reports. It is believed to be the first ever airline in the US to do so.
So far, the company confirms, two awards have been paid out, both to a total of one million miles each. At the time of writing, that equates to 16 round-trip economy tickets from Europe to the US, with change left over.
The US airline has been hit by a series of high-profile cyber gaffes over the past few months, including one instance of a security expert claiming to have hacked into his plane's avionics through the in-flight entertainment, and two separate occasions where technical faults grounded United Airlines planes nationwide.
However, the bounty programme comes with certain restrictions. "Onboard Wi-Fi, entertainment systems or avionics", for example, are all off-limits. This is to do with safety concerns, as unauthorised access to critical flight systems could prove hugely dangerous.
The terms of the agreement also prevent disclosure of the bug, as well as exploiting it at any point.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Bug bounties are a common practice among tech-savvy start-ups, but have yet to see widespread adoption outside of the world of IT. If United Airlines proves successful with its programme, this could signal the start of a new wave of bounty-hunting.
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
How the UK MoJ achieved secure networks for prisons and offices with Palo Alto Networks
Case study Adopting zero trust is a necessity when your own users are trying to launch cyber attacks
By Rory Bathgate
-
Putting small language models under the microscope
ITPro Podcast The benefits of small language models are undeniable – but they're no silver bullet
By Rory Bathgate
-
British Airways reveals massive data breach, could face £500m fine under GDPR
News The financial and personal details of 380,000 customers were stolen in the hack
By Clare Hopping
-
EU calls EU Passenger Name Record 'unreasonable'
News The plans to track passenger details is also unjustified, even though it's designed to combat terrorism
By Clare Hopping
-
Aeroplane Wi-Fi vulnerable to hacks, FAA report reveals
News The research by the US Government Accountability Office warned IP networks leave flights open to cyber attacks
By Clare Hopping
-
Should you be worried about the BA frequent flyer account hack?
News Hackers have reportedly gained access to thousands of British Airways frequent-flyer accounts
By Caroline Preece
-
Public Wi-Fi hotspots in hotels and conference centres pose remote access risk
News The vulnerability allows read and write access to an invidual or network's Linux file system
By Clare Hopping
-
Oyster card ‘free travel’ hack to be released
News Research behind a hack of the Oyster card will be released which has serious implications for cards using the same MIFARE chip around the world
By Asavin Wattanajantra
-
Government launches £9m internet safety ad campaign
News The plan, meant to raise awareness of the dangers of the internet, will launch this summer.
By Danielle Nordine