The author of the article describes how they gained access to an airline's systems through an exposed Jenkins server, ultimately obtaining a copy of the US TSA's no-fly list from 2019. The author found the list in a CSV file, which contained over 1.56 million rows of data. The author claims to have obtained the list with relatively little skill required, aside from patience and knowledge of where to look. The list has been made available to journalists and human rights organizations.