LmCast :: Stay tuned in

220 million traveler records exposed in Vietnam-linked APIS leak

Recorded: Sept. 8, 2026, 8 a.m.

Original Summarized

220 million traveler records exposed in Vietnam-linked APIS leak

News

Featured
Latest

Trezor data breach impact now reaches 81,000 customers

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

220 million traveler records exposed in Vietnam-linked APIS leak

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Mathspace discloses data breach affecting over 1 million people

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurity220 million traveler records exposed in Vietnam-linked APIS leak

220 million traveler records exposed in Vietnam-linked APIS leak

By Ax Sharma

September 8, 2026
03:35 AM
0

An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it.
Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country.
The exposed records span January 2017 to April 2026 and could involve travelers of many nationalities who flew to, from, or through Vietnam during that period.
Nine years of passenger and crew data
Kinryū Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity.
The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries.
According to Kinryū Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system.
The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries.
Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems.
Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others.

Sample database records showing passenger names, nationalities, passport information, and flight details
(Kinryū Labs)
While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.
Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers' own travel to Vietnam.
The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.
Database accessible through chained misconfigurations
Kinryū Labs told BleepingComputer that it reached the database by chaining two misconfigurations.
From the open internet, the endpoint returned an HTTP 401 "Unauthorized" response, preventing direct access to the database. However, a cloud-based path enabled researchers to reach the cluster, which then accepted default credentials.
Internet intelligence platform FOFA first recorded the host and port in October 2022 and identified the service as a database in July 2023. However, Kinryū Labs could not determine when the passenger data first became retrievable through the second access path.
As a result, while the records themselves span more than nine years, the actual length of the exposure is unknown.
Kinryū Labs said it reported the issue to Vietnamese authorities, airlines represented in the database, and national computer emergency response teams beginning June 3. The researchers said access to the database was remediated on June 8.
An authenticated email reviewed by BleepingComputer shows that Singapore Airlines' security team helped coordinate the response, informing Kinryū Labs on June 8 that it had "engaged the relevant parties" and "taken steps to contain the issue." Singapore Airlines did not provide an additional comment to BleepingComputer.
The findings shared with BleepingComputer identify several major airlines whose passenger records appeared in the database. However, there is no indication that the airlines operated the exposed system or that their own networks were compromised.
Changi Airport Group, which manages and operates Singapore's Changi Airport, told BleepingComputer that it had investigated the matter but declined to comment.
BleepingComputer also contacted Vietnamese authorities well in advance of publication but received no response.
It remains unclear whether the database was downloaded, sold, ransomed, or otherwise exploited by malicious actors before it was secured. Kinryū Labs said it found no ransom notes or unfamiliar indices on the cluster and could not identify the dataset being offered for sale online.
However, without access to server logs, the researchers could not conclusively determine whether anyone had copied the data.
Kinryū Labs expects to publish additional technical findings on its blog later this week.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
IDScan sued over alleged data breach affecting 153 million driversFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataExfilSquad hackers leak info of over 100,000 UK police officers, staffCoca-Cola confirms data theft in Fairlife ransomware attackDentaQuest data breach exposed info of 2.6 million accounts

Data Breach
Data Leak
Passport
Vietnam

Ax Sharma
Ax Sharma is a security researcher and journalist focused on malware analyses and cybercrime investigations. His expertise includes open source software security, threat intel analysis, and reverse engineering. Frequently featured by leading media outlets like the BBC, Channel 5 (UK), Fortune, WIRED, among others, Ax is an active community member of the OWASP Foundation and the Canadian Association of Journalists (CAJ).

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Attackers conceal phishing lures using invisible Unicode characters

Sponsor Posts

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Can you trust every session? See how session enrichment enables better authentication decisions.

Unify ransomware protection and recovery for every client

CTI Starter Kit + 2026 SANS CTI Survey

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

An Advance Passenger Information System (APIS) database containing over 220 million passenger and crew records, including passport numbers and flight details, was discovered exposed online through a series of security misconfigurations reportedly linked to a Vietnamese organization. This data breach involved information spanning from January 2017 to April 2026, covering nine years of travel data for individuals who flew to, from, or through Vietnam during that period. The exposure originated from an Elasticsearch cluster named 'pax-info,' which Kinryū Labs discovered while investigating ransomware activity in exposed databases. This cluster contained approximately 220,783,700 entries, comprising 210,318,069 passenger records and 10,465,631 crew records.

The exposed information was highly sensitive, including names, dates of birth, sex, nationalities, passport or travel document numbers, document expiration dates, issuing countries, as well as associated travel details such as flight numbers and dates, airline information, departure and destination airports, transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times. While the researchers could not provide a precise breakdown by nationality, the data included travelers from numerous nationalities across the Asia-Pacific, Europe, and the Middle East, indicating global scope. Kinryū Labs verified the legitimacy of the information by cross-referencing the database entries with their own travel history to Vietnam.

The researchers determined that access to the database was achieved by chaining two distinct security misconfigurations; initially, an endpoint returned an HTTP 401 Unauthorized response, which prevented direct access. However, a cloud-based path allowed researchers to reach the cluster, which then accepted default credentials subsequent to identification of the host and port by internet intelligence platforms. Although the records span more than nine years, the actual duration of the data exposure remains undetermined.

Following the discovery, Kinryū Labs reported the issue to Vietnamese authorities, relevant airlines represented in the database, and national computer emergency response teams starting June 3, initiating a coordinated response. Singapore Airlines' security team assisted in this containment effort by informing researchers on June 8 that they had engaged relevant parties and taken steps to contain the issue. The exposed findings implicated several major airlines whose records were present in the database, though there was no indication that these airlines operated the compromised system or had been directly breached themselves. Authorities, including Vietnamese officials, were contacted in advance of the publication, although no formal response was received by BleepingComputer. The researchers found no evidence of ransom notes or unfamiliar indices on the cluster, but conclusively determining whether malicious actors exploited and copied the data before security measures were implemented is not possible without access to server logs.