The data was sitting on the public internet in an unsecured computer server hosted by CommuteAir, a regional airline based in Ohio, according to the hacker claiming the discovery. The hacker, who also describes herself as a cybersecurity researcher, told CNN she notified CommuteAir of the data exposure.