220 million traveler records exposed in Vietnam-linked APIS leak
Recorded: Sept. 8, 2026, 8 a.m.
| Original | Summarized |
220 million traveler records exposed in Vietnam-linked APIS leak News Featured Trezor data breach impact now reaches 81,000 customers BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations N-able patches max severity N-central flaw amid ongoing attacks Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain 220 million traveler records exposed in Vietnam-linked APIS leak Magento StyleSmuggler zero-day exploited to deploy Linux backdoor BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Mathspace discloses data breach affecting over 1 million people Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurity220 million traveler records exposed in Vietnam-linked APIS leak 220 million traveler records exposed in Vietnam-linked APIS leak By Ax Sharma September 8, 2026 An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Sample database records showing passenger names, nationalities, passport information, and flight details Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Data Breach Ax Sharma Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories OpenAI admits it didn't disclose rogue AI wiki hijacking incident Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain Attackers conceal phishing lures using invisible Unicode characters Sponsor Posts See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Can you trust every session? See how session enrichment enables better authentication decisions. Unify ransomware protection and recovery for every client CTI Starter Kit + 2026 SANS CTI Survey Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
An Advance Passenger Information System (APIS) database containing over 220 million passenger and crew records, including passport numbers and flight details, was discovered exposed online through a series of security misconfigurations reportedly linked to a Vietnamese organization. This data breach involved information spanning from January 2017 to April 2026, covering nine years of travel data for individuals who flew to, from, or through Vietnam during that period. The exposure originated from an Elasticsearch cluster named 'pax-info,' which Kinryū Labs discovered while investigating ransomware activity in exposed databases. This cluster contained approximately 220,783,700 entries, comprising 210,318,069 passenger records and 10,465,631 crew records. The exposed information was highly sensitive, including names, dates of birth, sex, nationalities, passport or travel document numbers, document expiration dates, issuing countries, as well as associated travel details such as flight numbers and dates, airline information, departure and destination airports, transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times. While the researchers could not provide a precise breakdown by nationality, the data included travelers from numerous nationalities across the Asia-Pacific, Europe, and the Middle East, indicating global scope. Kinryū Labs verified the legitimacy of the information by cross-referencing the database entries with their own travel history to Vietnam. The researchers determined that access to the database was achieved by chaining two distinct security misconfigurations; initially, an endpoint returned an HTTP 401 Unauthorized response, which prevented direct access. However, a cloud-based path allowed researchers to reach the cluster, which then accepted default credentials subsequent to identification of the host and port by internet intelligence platforms. Although the records span more than nine years, the actual duration of the data exposure remains undetermined. Following the discovery, Kinryū Labs reported the issue to Vietnamese authorities, relevant airlines represented in the database, and national computer emergency response teams starting June 3, initiating a coordinated response. Singapore Airlines' security team assisted in this containment effort by informing researchers on June 8 that they had engaged relevant parties and taken steps to contain the issue. The exposed findings implicated several major airlines whose records were present in the database, though there was no indication that these airlines operated the compromised system or had been directly breached themselves. Authorities, including Vietnamese officials, were contacted in advance of the publication, although no formal response was received by BleepingComputer. The researchers found no evidence of ransom notes or unfamiliar indices on the cluster, but conclusively determining whether malicious actors exploited and copied the data before security measures were implemented is not possible without access to server logs. |