By T2 Editors1 day ago

Summary

The Securities and Exchange Commission purchased warrantless access to more than one billion airline booking records from the Airlines Reporting Corporation’s Travel Intelligence Program — a database containing passenger names, credit card numbers, flight details, and itineraries including trips entirely outside the United States. The civil regulator used a daily alert system that flagged individuals against agency watchlists, requesting between one and 25 alerts each day.

Though the program was shuttered by the end of 2025 after lawmaker pressure, the newly revealed scale of surveillance leaves urgent questions about what data was amassed and who else had access. Travelers who booked through agencies or third-party portals were directly exposed, and the SEC’s FOIA office still accepts Privacy Act requests to check individual records.

The Securities and Exchange Commission — a civil financial watchdog — secretly tapped a post‑9/11 surveillance pipeline designed for counterterrorism, using commercially acquired travel data to monitor individuals worldwide without a warrant or suspicion of crime. Newly obtained documents reveal the Airlines Reporting Corporation (ARC), co‑owned by American Airlines, Delta, and United, aggregated booking information from over 270 carriers and thousands of travel agencies into a single intelligence product that the SEC mined for investigations.

That data trove included not just flight numbers and dates but credit card details, departure and arrival cities, and the selling agency — enough to reconstruct an entire journey.

The alert function could flag new bookings within 24 hours, enabling near‑real‑time tracking. Scope was global: journeys between two foreign countries were swept in alongside U.S.‑related itineraries. Business‑class flyers who book through corporate travel desks or online agencies had their data fed directly into the system because ARC obtained records exclusively from agency‑ and portal‑sold tickets, not direct airline purchases. The program, which ceased operations by the end of 2025, leaves behind a vast archive of sensitive traveler information and a stark warning about how commercial data pipelines bypass constitutional safeguards.

The surveillance infrastructure that turned trip data into a government tool

ARC’s Travel Intelligence Program began as a post‑9/11 data‑sharing mechanism for law enforcement, but its customer list widened to include the SEC — a regulator with no national security mission. The records contained names, credit card numbers, departure and arrival cities, flight numbers and dates, and the travel agency that issued each ticket. Daily alerts matched passengers against agency watchlists, with the SEC requesting between one and 25 hits per day, each capturing travel booked in the preceding 24 hours.

ARC announced the program’s termination in November 2025 after pressure from lawmakers, and it ended that year. But the newly released documents confirm the SEC’s access was far broader than previously known, with the database covering both U.S.‑related and entirely foreign itineraries. The shutdown does not erase the data already collected, nor the precedent set for using commercial purchases to avoid judicial oversight.

Timeline of the ARC Travel Intelligence Program and SEC involvement
Date / Period Event Impact
Post‑9/11 ARC launches Travel Intelligence Program Created for intelligence and law enforcement, aggregates agency‑booked passenger data globally.
Unknown SEC subscribes to TIP Regulator gains access to over one billion records and a daily name‑match alert system.
November 2025 ARC announces TIP shutdown Program ceases by end 2025 after congressional pressure; commercial pipeline stops.
August 2026 FOIA documents released Scale of SEC surveillance disclosed; privacy and Fourth Amendment debate intensifies.
ATC

Flight deals most people never see

Our AI monitors 150+ airlines for pricing anomalies that traditional search engines miss. Air Traveler Club members save $650 per trip per person on average: see how it works.


Each deal saves 40–80% vs. regular fares:

Superdeals preview

The privacy breakdown: why even civil regulators can track your movements

The SEC’s use of ARC’s data reveals a systemic vulnerability: commercially purchased travel records let government agencies bypass warrant requirements that would apply if they demanded the information directly. And the SEC was not alone — the program also supplied the FBI, IRS, and Department of Homeland Security, creating a sprawling surveillance ecosystem that treated passenger booking data as a commodity.

Air Traveler Club’s analysis of the JetBlue surveillance pricing lawsuit underscores the growing tension between airline data monetization and passenger privacy — a conflict now starkly visible in the SEC’s ARC data purchase. For premium travelers, the key insight is that booking channel determines exposure: agency‑ and portal‑sold tickets fed the surveillance pipeline, while direct airline bookings fell outside ARC’s collection scope.

How to reduce surveillance exposure after the SEC’s ARC data sweep

While the Travel Intelligence Program is closed, the disclosure makes clear that your booking channel directly determines whether your data ends up in government databases — making future choices a privacy consideration.

  • Submit a Privacy Act request to the SEC to see what records they hold on you. This is the only way to verify past exposure.
  • Book direct with airlines for future travel. Direct‑booked tickets were not part of ARC’s data stream, cutting off that surveillance path entirely.
  • If you must use an agency, request a copy of your reservation record and understand that data may be shared with clearinghouses — even for itineraries that never touch U.S. soil.
  • Monitor congressional actions targeting warrantless commercial data purchases. A hearing or bill text could emerge within weeks, signaling the move from reporting to policy fight.
  • Consider loyalty‑portal bookings or privacy‑focused agents that commit to not sharing data beyond necessary fulfillment, reducing intermediary handoffs.

Watch for SEC FOIA disclosures or congressional hearings — expected in the coming weeks — that could illuminate the full list of agencies that tapped ARC’s data. If additional civil regulators are named, the surveillance footprint will prove even wider than the current disclosure suggests.

Reporting by

T2.0 Editors

Since 2010, we've tracked global aviation markets across four continents, monitoring 150+ airlines and their route networks, fare structures, and seasonal dynamics. Our team delivers daily aviation intelligence — combining technology with on-the-ground market knowledge.

FAQ

Did the SEC collect my airline booking records?

If you booked through a travel agency, online travel agency, or corporate desk between the program’s inception and its shutdown at the end of 2025, your itinerary, name, and payment details may have been swept into ARC’s database and potentially accessed by the SEC. Direct airline bookings were not included.

Can I find out what data the SEC holds on me?

Yes. Submit a Privacy Act request through the SEC’s FOIA office. Provide your identity and specify travel records. The SEC accepts requests online at SEC.gov, by email to foiapa@sec.gov, by fax, or by mail.

How can I avoid similar surveillance in the future?

Book flights directly with airlines whenever possible; direct purchases sidestep ARC’s data aggregation. Keep records, and if privacy is critical, use travel agents who commit to not sharing data beyond necessary fulfillment.