Usual preface this is strictly and soley from a security / privacy interest to the exclusion of everything else : https://www.theregister.com/2025/05/12/globalx_security_incident/
… “On May 5, 2025, Global Crossing Airlines Group learned of unauthorized activity within its computer networks and systems supporting portions of its business applications, which the company determined to be the result of a cybersecurity incident,” an SEC filing from May 9 reads. … The disclosure, however vague, lends credence to reports that those responsible had stolen flight records and passenger manifests, including ones related to deportation flights, dating back to January. …
TheRegister closes with a link to GlobalX’s 10-K about “maintains robust cybersecurity controls through risk assessments, system monitoring, information security policies, and employee awareness and training.” The 404media link specifies that the hackers found a token beloging to GlobalX dev, which then lead to access and secret keys to GlobalX’s AWS instances.
…so about that key you left under the porch rug…
/sarcasm
Regards