A study by Flare has revealed how public data can be used to map parts of the IT infrastructure of certain North American airports. Researchers identified hundreds of compromised identifiers, including that of a two-factor authentication console stolen by an infostealer. Although the airports studied may keep their critical systems offline from the Internet, their cybersecurity leaks far more clues than one might imagine. In September, researchers from Flare cross-referenced passive DNS, IP address ranges, and databases of compromised identifiers to identify 165 named systems, ranging from flight displays to fuel management, and 253 employee accounts whose identifiers are circulating in the wild. This provides a detailed map of the location before even the first hook. A spyware program stole the identifier that controls the two-factor authentication of an airport. Since the ransomware attack against Collins Aerospace that occurred just over a year ago, which had disrupted registration at Brussels, Berlin, and London-Heathrow, airport cybersecurity remains highly monitored. Flare examined three email domains identified in data leaks out of the fourteen email domains identified (the part that follows the @ in employees' addresses). The total number of records rises to 950, each linking an address to a password for 253 accounts, knowing that the same employee can appear in multiple leaks. In 81 percent of cases, the password is readable as is, and not masked with an indecipherable string of characters. However, it should be somewhat relativized, since 930 lines come from compilations that recycle old leaks, some dating back to 2008. Nothing is buried, however, since 147 accounts appeared in the last two years. Flare did not test any passwords, so it is unknown how many still work. The real danger concerns five accounts, whose identifiers do not come from old archives, but from recent infections or targeted attacks. They were sucked up by infostealers, spyware that silently steals passwords stored on a computer, or trapped by phishing kits, these ready-made fake login pages. One of them concerns a strategic position, namely the administration console of the multi-factor authentication (MFA) of an operator, which decides who must confirm their connection with a code or a notification, and how. This identifier, captured in April 2026 on an infected Windows 11 PC, could, if the account has the rights, be used to modify these rules, to register a new device, or to activate exceptions. The protection intended to cover the other exposed accounts of this operator would lose its effectiveness. The infostealer's haul is rather significant. In the lot, one finds the IP address, the user's session name, the hardware-specific identifier, the Windows version, and even the location. One also finds the two email domains of the operator, buried in a long list of personal accounts. The profile suggests a personal computer, or at least one not managed by the IT department, but used for work. As another signal, one of the domains studied appeared in five Telegram messages in May and June 2026. Three come from a bot that checks if email addresses are valid, on the support channel of an online sales platform, and two from channels that retransmit leaks. Someone is therefore closely interested in it.