{"id":34755,"date":"2020-04-30T22:48:16","date_gmt":"2020-04-30T22:48:16","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/"},"modified":"2020-04-30T22:48:16","modified_gmt":"2020-04-30T22:48:16","slug":"quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/","title":{"rendered":"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers"},"content":{"rendered":"<p>Short-video biz Quibi, airline JetBlue, shopping site Wish, and several other companies leaked million of people&#8217;s email addresses to ad-tracking and analytics firms through HTTP request headers, it is claimed.<\/p>\n<p>According to <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/medium.com\/@thezedwards\/the-2020-url-querystring-data-leaks-millions-of-user-emails-leaking-from-popular-websites-to-39a09d2303d2\">findings<\/a> published Wednesday by Zach Edwards, of digital strategy firm Victory Medium, these businesses have spilled these contact details to advertising networks and the like over the past few years. Among those websites identified by Edwards \u2013 a group that also includes Mailchimp, The Washington Post, NGPVan.com, KongHQ, and GrowingChild.com \u2013 some promptly altered their websites when notified of the issue, but others have not.<\/p>\n<p>And while this disclosure of email addresses to third parties may well be covered in high-level terms buried in corporations&#8217; privacy policies, it&#8217;s a reminder of just how easy it is for websites to pass along your personal contact details in a blink of an eye without you realizing.<\/p>\n<p>Netizens using web browsers that prioritize defenses against ad tracking, such as Brave, Firefox, and Safari, or who have installed suitable privacy extensions in other browsers, may have avoided having their email addresses spirited away.<\/p>\n<h3 class=\"crosshead\"><span>How it happens<\/span><\/h3>\n<p>When someone tries to visit a page on a website \u2013 by clicking on a link or button, say \u2013 their browser constructs a <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Overview\">HTTP request<\/a> for that page, and sends it to the website. That request contains a URL address for the page, and this URL can contain information relevant to the request. The HTTP request also can contain what&#8217;s called a <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Headers\/Referer\">referer<\/a> header, which specifies the URL for the webpage you just visited.<\/p>\n<p>Now imagine you click on a link to a webpage, and its URL contains your email address. Your browser requests and receives that webpage, which then tells your browser to automatically go fetch files, such as images and JavaScript code, from other websites. When your browser requests those follow-up files, the referer header in the HTTP requests will be the URL you just opened \u2013 which, don&#8217;t forget, contains your email address. That webpage has now leaked your contact details to those other sites.<\/p>\n<p>Quibi, the recently launched short video sharing app, was doing just that, said Edwards. When a new user signed up with an email address, that person received an email with an account creation confirmation link. Clicking on that link took the netizen to a webpage with the following URL, which contained their account email address:<\/p>\n<pre class=\"wrap_text\">\nhttps:\/\/quibi.com\/email_verified\/?email=user%40gmail.com&...\n<\/pre>\n<p>That verification page, when fetched, automatically reached out to other servers to request JavaScript code and other files \u2013 with that verification page&#8217;s URL, containing the sign-up address, in the referer header of the HTTP requests. In effect, Quibi shared the user&#8217;s email address in plaintext to ad partners, such as Google&#8217;s DoubleClick, Google Tag Manager, Google Analytics, Facebook Analytics, Twitter, Snapchat, and others. Those websites would be able to link your interest in Quibi to your email address for the purpose of targeting you with tailored ads, for instance.<\/p>\n<p>Quibi did not immediately respond to a request for comment. According to Edwards, the company is no longer spilling email addresses as described above. Quibi&#8217;s <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/quibi.com\/privacy-policy\/\">privacy policy<\/a> states it does share people&#8217;s info with ad networks, though there&#8217;s no specific mention of email addresses being shared in this way.<\/p>\n<p>JetBlue, it&#8217;s claimed, similarly leaked email addresses from a signup webpage, and was alerted to the shortcoming in March. &#8220;After being informed of the leak, JetBlue stated they would never do what they are doing because it would be against the law,&#8221; Edwards said in his report.<\/p>\n<p>The airline did not immediately respond to a request for comment. Again, like with Quibi, the <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.jetblue.com\/legal\/privacy\">privacy policy<\/a> states email addresses may be disclosed for commercial purposes, though doesn&#8217;t explicitly say how.<\/p>\n<p>For the past two years, Wish.com has been transmitting millions of email addresses, in base64 encoding, which is not encryption, we&#8217;re told.<\/p>\n<p>&#8220;From July 2018 until January 2020 when this research was initially shared with Wish.com, Wish transmitted user emails to at least Google, Facebook, Pinterest, Criteo, PayPal and Stripe, and potentially other companies,&#8221; Edwards said. Several thousand of these messages apparently have been cached by search engines such as URLscan.io.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2017\/07\/19\/footprints_sand_photo_via_shutterstock.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"Footprints sand photo via Shutterstock\"><\/p>\n<h2 title=\"Gap in browser privacy tech embarrassingly detected by Google\">You had one job, Cupertino: Apple&#8217;s Intelligent Tracking Protection actually gets tracking protection<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2019\/12\/12\/apple_intelligent_tracking_protection\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>Glenn Lehrman, veep and head of communications at Wish.com, told <em>The Register<\/em> the company considers data protection and user trust a top priority. He said after receiving Edwards&#8217; report earlier this year, the biz made some changes, including adding encryption to protect user email addresses in transit.<\/p>\n<p>Lehrman said he disagreed with Edwards&#8217; findings, noting that the websites receiving the email addresses act as service providers, performing advertising and sales support functions.<\/p>\n<p>&#8220;Zach takes issue with the specific manner in which web referer data was encoded (into a non-human readable string) and surmises that large service providers theoretically could have first ingested and then taken steps to decode that data,&#8221; said Lehrmann. &#8220;We have no reason to believe that occurred. Certainly, these companies had no reason to do so, and in any event, it certainly is not a &#8216;breach&#8217; to provide a service provider with such encoded information.&#8221;<\/p>\n<p>Email addresses are considered Personally Identifiable Information under Europe&#8217;s General Data Protection Regulation, Edwards told <em>The Register<\/em>. Exposing this data could pose problems to companies operating in Europe.<\/p>\n<p>The California Consumer Privacy Act is less clear. &#8220;That&#8217;s why Wish said all its ad tech partners were &#8216;service providers&#8217; \u2013 this is the one opening in the CCPA to be able to share data this way,&#8221; he added.<\/p>\n<p>Even so, Edwards believes none of the organizations he identified made this data sharing sufficiently clear in their privacy policies.<\/p>\n<p>Edwards said he doubts these leaks are accidental. &#8220;It\u2019s definitely not an accident when most organizations do this,&#8221; he said, noting that the practice is a widely known and heavily used &#8220;growth hack.&#8221;<\/p>\n<p>&#8220;It improves retargeting opportunities and improves attribution in analytics systems,&#8221; he said. &#8220;Ad tech Companies like Adroll had a &#8216;data shotgun&#8217; that grabbed emails in URls for years and this is a known strategy. Liveramp has a user graph with huge amounts of emails and tons of ad networks have email matching like Facebook Custom Audience. Email being pushed to ad networks is almost always on purpose and it&#8217;s profitable for folks who do it.&#8221; \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1916\/-8373\/practical-tips-for-office-365-tenant-to-tenant-migration?td=wptl1916\">Practical tips for Office 365 tenant-to-tenant migration<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/go.theregister.co.uk\/feed\/www.theregister.co.uk\/2020\/04\/30\/email_http_leakage\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>From URL to UR-Hell Short-video biz Quibi, airline JetBlue, shopping site Wish, and several other companies leaked million of people&#8217;s email addresses to ad-tracking and analytics firms through HTTP request headers, it is claimed.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":34757,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-34755","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-30T22:48:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers\",\"datePublished\":\"2020-04-30T22:48:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/\"},\"wordCount\":1088,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/\",\"name\":\"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg\",\"datePublished\":\"2020-04-30T22:48:16+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/","og_locale":"en_US","og_type":"article","og_title":"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-04-30T22:48:16+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers","datePublished":"2020-04-30T22:48:16+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/"},"wordCount":1088,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/","url":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/","name":"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg","datePublished":"2020-04-30T22:48:16+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/quibi-jetblue-wish-others-accused-of-leaking-millions-of-email-addresses-to-ad-orgs-via-http-referer-headers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=34755"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34755\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/34757"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=34755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=34755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=34755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}