Unverified claim: On July 26, 2026, a group calling itself ExfilSquad listed Frontier Airlines on a leak site and claimed roughly 43GB / 2.4 million records from a customer-support portal — via misconfigured Microsoft Power Apps / Dynamics 365 Dataverse permissions. Frontier had not confirmed that claim when DataBreaches.net reported it. Do not treat 2.4 million as company-confirmed.
Canonical claim row: Frontier ExfilSquad claim. Separate verified storage breach (~11,482 people): May–June 2026 disclosure.
What ExfilSquad says it took
According to the listing and a follow-up statement to DataBreaches, ExfilSquad is not claiming affiliation with ShinyHunters. The group says its current leak-site victims stem from Microsoft Power Apps / Dynamics 365 misconfigurations — specifically improper Dataverse table permissions — not from the May–June storage-account intrusion Frontier already disclosed.
Actor-side numbers cited in that reporting: about 589,554 support tickets, 1,836,608 customer-support email communications, and around 2 million unique email addresses, packaged as ~43GB uncompressed and marketed as ~2.4 million records covering support cases, flight/travel information, complaints, baggage details, and support email traffic. The listing gave Frontier until August 5 to make contact.
DataBreaches emailed Frontier and its CISO. No reply had arrived by publication. That silence is not confirmation. Until Frontier, a state AG notice, or another primary attestation ties those Dataverse tables to a confirmed intrusion, BreachHistory keeps companyConfirmed false and labels every 2.4 million figure as actor/reporter count only.
Do not confuse this with the confirmed 11,482-person breach
Frontier already has a verified 2026 incident: unauthorized access to a data storage account from about May 12 through June 3, discovered around June 18, with notices rolling out in July for roughly 11,482 employees and passengers. Trade press and litigation coverage describe names, addresses, Social Security numbers, driver’s licenses and other government IDs, and related personal information among categories that could vary by person.
Early reporting briefly tied Scattered Lapsus$ Hunters branding to that storage breach. DataBreaches later corrected the record after a ShinyHunters-associated Telegram account denied that Scattered Lapsus$ Hunters claimed, targeted, or attacked the airline — and denied ShinyHunters involvement as well. BreachHistory’s verified row title no longer leads with that attribution.
ExfilSquad’s July 26 listing is a third narrative in the same news cycle, not an automatic expansion of the 11,482 count. Searching “Frontier Airlines data breach 2026” should surface both the attested storage incident and this separate unverified Power Apps claim.
The BobDaHacker vulnerability thread sits beside both stories
In June 2026, researcher writing as BobDaHacker published that Frontier had been notified in March about serious booking-path issues: a mobile app API that returned a raw internal booking object when given only a PNR and last name — data printed on boarding passes — plus Manage My Booking pages that leaked unmasked emails and phones in page source, and a client-side analytics blob that still exposed Known Traveler Numbers in plaintext after a partial fix.
Frontier told Cybernews it had addressed and resolved potential IT vulnerabilities. The researcher’s updates disputed that some sensitive client-side exposure remained. Whether those bugs connected to the May–June storage breach, or to anything ExfilSquad claims, is unknown. What is clear: low-friction booking PII exposure and a SaaS CRM permission mistake are different failure modes. Passengers should not collapse them into one “Frontier was hacked once” mental model.
Why a Power Apps / Dataverse claim matters for travelers
Airlines run customer-support workloads on Microsoft cloud stacks because agents need tickets, case history, and email threads next to itineraries. Dataverse tables holding support mail are dense with freestyle text: phone numbers, loyalty IDs, complaint narratives, baggage claim numbers, and sometimes government ID details passengers paste into replies.
If ExfilSquad’s description is accurate, the blast radius is not only “2 million emails.” It is years of support conversations that teach attackers how to sound like Frontier’s care team. Phishing that quotes a real complaint subject line or a delayed-bag claim number will outperform generic “your flight was cancelled” spam.
What this is not: proof that every Frontier flyer’s passport sits in that dump. Actor listings maximize volume metrics. Unique email counts can include employees, vendors, one-off contacts, and duplicates across ticket threads. Treat ~2 million unique emails as an upper-bound marketing number until Frontier publishes a field inventory.
Who should care most
People who opened Frontier support cases in recent years — delayed bags, refund disputes, wheelchair assists, irregular operations — because their threads are exactly what a support-portal dump would contain.
Anyone who already received a July notice for the verified ~11,482 storage breach should still follow that letter’s credit-monitoring and freeze guidance. The ExfilSquad claim does not replace that notice; it adds a separate phishing risk.
Crew and corporate staff whose work emails appear in support CC fields should expect targeted invoice-fraud and MFA-fatigue attempts that cite “ExfilSquad” or “Power Apps leak” as urgency bait.
Travelers who only booked and never contacted support still face opportunistic scams that name Frontier. Absence from a support dump does not stop attackers from spoofing flyfrontier.com lookalikes.
Airline SaaS extortion in 2026
2026 leak sites increasingly advertise “misconfigured SaaS” rather than classic ransomware encryption. Power Apps, Salesforce, and Zendesk-class portals show up because oversharing a security role can dump an entire customer table without malware on a laptop.
ExfilSquad’s self-description — that current listings come from Dataverse permission mistakes — fits that pattern. Whether Frontier’s configuration was actually exposed remains unproven publicly. The claim still teaches defenders: review Dataverse table permissions, guest access, and Power Apps sharing links the way you review S3 buckets.
Compare this story to other large unverified airline and travel claims in the catalog: always separate companyConfirmed true rows from leak-site marketing. Scale alone is not verification.
Action items if you fly Frontier
- Prefer official Frontier apps and bookmarked https://www.flyfrontier.com pages over search ads promising “breach payouts.”
- If you got a July notice for the ~11,482 storage incident, enroll in offered monitoring and freeze credit at Equifax, Experian, and TransUnion.
- Assume support-email phishing will quote real itinerary or bag-claim details; verify callbacks only through numbers on your boarding pass or the official site.
- Change passwords if you reused a Frontier account password on email; enable MFA on email first.
- Watch bank and card statements for small airline-adjacent charges after any support dispute.
- Do not send passport scans or SSN “re-verification” forms that arrive by unexpected email citing ExfilSquad.
- Employees: treat wire-change and gift-card requests that mention the leak site as fraud until verified out-of-band.
- Follow Frontier’s official investor/press channels for any future confirmation — not Telegram screenshot chains.
Canonical records and sources
Unverified claim: https://breachhistory.com/frontier-airlines/frontier-exfilsquad2026. Verified storage breach: https://breachhistory.com/frontier-airlines/frontier-airlines-scatteredlapsus2026. Primary reporting: DataBreaches.net (corrected); researcher write-up context via BobDaHacker’s Frontier boarding-pass / Manage My Booking posts as covered in that article.
Timeline passengers can actually use
March 3, 2026 (per BobDaHacker): researcher says Frontier was notified of critical booking-path issues.
May 12–June 3, 2026: window of unauthorized access to a data storage account described in later litigation and AG-facing coverage for the verified incident.
June 16–21, 2026: public researcher posts and updates argue that some client-side exposures, including Known Traveler Number leakage, remained after a partial fix; Frontier tells press vulnerabilities were addressed.
June 18, 2026 (approx.): Frontier reportedly discovers the storage-account intrusion.
July 9–14, 2026: notification window cited for affected parties in the ~11,482 incident.
July 15, 2026: federal lawsuit activity tied to the storage breach appears in trade coverage.
July 26–27, 2026: ExfilSquad lists Frontier; DataBreaches publishes actor detail and later corrects Scattered Lapsus$ Hunters attribution on the earlier hack narrative.
August 5, 2026: actor-stated contact deadline on the ExfilSquad listing — not a regulator deadline.
What data types mean in practice
Support tickets and complaint text are gold for social engineering. An attacker who knows you argued about a $75 bag fee can open with empathy and then ask you to “re-submit ID for the refund.”
Flight and travel fields help craft SMS that name real dates and cities. Baggage details support fake “pay a delivery fee to release your bag” pages.
Email archives often contain outbound agent replies with policy language passengers already trust. Spoofing those templates is trivial once samples circulate.
Government ID numbers were highlighted in the verified storage breach coverage. ExfilSquad’s public summary emphasized support CRM volume; do not invent passport columns that Frontier has not confirmed for the Dataverse claim.
How journalists and advocates should cover two numbers
Headline A: Frontier notifies about 11,482 people after a storage-account breach. Headline B: ExfilSquad claims 2.4 million records from a support portal. Both can appear in the same Google results for “Frontier Airlines data breach.” The disciplined reading is that A is attested and B is contested marketing until proven.
Advocates helping travelers should send two links — verified and claim — the way BreachHistory does for other dual narratives. Mixing them into one “millions of Frontier flyers breached” sentence is how false certainty spreads.
If Frontier later confirms a Power Apps incident, expect a cleaner data-element list and a count that may not match 2.4 million rows. Catalog rows will update; until then labels stay strict.
Defender checklist for airline Microsoft estates
Inventory every Power App connected to customer-support Dataverse tables. Remove orphaned apps and guest shares.
Review security roles that grant organization-wide read on contact, email, and case tables. Least privilege beats hoping attackers never find the URL.
Log and alert on bulk Dataverse exports and unusual Power Automate flows that dump tables to anonymous storage.
Separate researcher-reported boarding-pass API flaws from SaaS CRM permission reviews in the incident postmortem. Different owners, different fixes.
Prepare customer-care scripts for the week after a leak-site listing: agents will be flooded with “was I in the 2.4M?” calls. Give them the verified 11,482 facts and an honest “we have not confirmed the ExfilSquad claim” line if that remains true.
Extended FAQ
Was Frontier Airlines breached for 2.4 million people? ExfilSquad claims a ~2.4M-record support-portal dump; Frontier had not confirmed at indexing. A separate verified incident affected about 11,482 people.
Is this ShinyHunters? ExfilSquad told DataBreaches it is not affiliated with ShinyHunters. ShinyHunters also denied targeting the airline in the storage-breach narrative.
I never opened a support ticket — am I safe? You may be outside a support dump and still targeted by opportunistic phishing that names Frontier.
Should I freeze credit? Yes if you received the verified-breach notice; still wise for frequent flyers watching SSN-related storage categories in that disclosure.
What about Known Traveler Numbers on Manage My Booking? That was a separate researcher finding about client-side exposure; treat KTN phishing as real regardless of ExfilSquad.
Sector context without inventing confirmation
Low-cost carriers process enormous booking and irregular-operations volumes with thin IT staffing relative to megacarriers. That economic model does not prove any particular claim. It does explain why researchers keep finding boarding-pass enumeration bugs and why SaaS CRM misconfigurations hurt when they happen.
Passengers comparing Frontier’s 2026 headlines to other airline incidents should ask two questions every time: Did the airline or a regulator attest a count? Is the leak-site number labeled as such? BreachHistory’s Frontier pages exist to keep those answers visible.
Lawyers filing class actions around the storage breach will watch whether ExfilSquad evidence ever enters discovery. Public readers should not treat lawsuit captions as proof of the Power Apps narrative.
Practical guidance for the next thirty days
Expect a wave of SMS and email lures through early August around the actor’s stated deadline. Scammers love countdown clocks.
If a caller claims to be Frontier fraud prevention and already knows your bag tag number, hang up and redial the number on the official site. Knowledge of support-thread trivia is not proof of legitimacy if a dump is real — and it is still not proof if the dump is fake.
Corporate travel managers should warn employees booking Frontier on company cards that gift-card “rebooking” scams spike after airline breach headlines.
Keep the BreachHistory claim URL and verified URL in your notes app so you can forward labeled summaries instead of screenshots when relatives panic-text.
Watch for any Frontier press statement that names Power Apps, Dataverse, or customer-support email archives. That wording — not Telegram bravado — is what would flip verification status.
Why dual catalog rows protect readers
Collapsing ExfilSquad’s marketing into the verified 11,482 disclosure would either inflate the attested count or bury a novel SaaS claim. Keeping two rows lets “Frontier Airlines breach” searchers see both the storage-account facts and the unverified CRM claim with matching labels.
The same discipline applies across 2026 healthcare and fintech extortion waves: actor terabytes and unique-email boasts are signals for investigators, not automatic census replacements.
If you only remember one line from this Frontier Airlines data breach update: 11,482 is the confirmed storage incident scale in public notices; 2.4 million is an unverified ExfilSquad Power Apps claim until Frontier says otherwise.
Reading ExfilSquad’s deadline without panicking
August 5 on a leak site is theater designed to force executives into rushed negotiations and to give scammers a calendar hook. Passengers cannot meet that deadline in any useful way. Paying a stranger who emails “ExfilSquad removal” does nothing for your itinerary and often empties a gift-card balance.
If Frontier confirms a customer-support portal incident later, the useful artifacts will be an official notice, a data-element list, and enrollment instructions — not a countdown clock on a criminal blog. Until then, treat every “pay before August 5 or your Frontier file goes public” message as fraud.
Security teams at peer airlines should still treat the listing as a tabletop prompt: who owns Dataverse roles, how fast can you revoke a overshared Power App, and what does customer care say on day one? That preparation helps whether or not Frontier’s specific claim ever hardens into a confirmed Frontier Airlines data breach addendum.