220 million traveler records exposed in Vietnam-linked APIS leak
Researchers found no ransom notes or data tampering, and investigators could not tell whether anyone copied the 220 million records before containment.
- On June 3, Kinryk Labs discovered an exposed Elasticsearch database containing over 220 million travel records linked to Vietnam, spanning nearly a decade of international flight data for passengers and crew.
- The database included sensitive travel-specific fields such as full names, dates of birth, passport numbers, and nationalities, spanning nine years of arrivals, departures, and transits through Vietnam from January 2017 through April 2026.
- Investigators traced the server to an IP address space assigned to Viettel, a telecommunications provider based in Hanoi; the 29 indices totaled roughly 107 GB of data accessed through two separate misconfigurations.
- After Kinryk Labs notified authorities and affected carriers on June 3, the cluster was secured by June 8; Singapore Airlines assisted in coordinating the response, while Changi Airport Group investigated but declined further comment.
- While researchers found no evidence of data alteration, they could not determine whether outside parties exfiltrated information before the cluster was secured. Travelers face phishing risks from this exposed data, as the organization responsible remains unidentified.
13 Articles
13 Articles
220 Million Traveler Records Exposed: Passport Details and Nine Years of Flight Data Left Unprotected in Vietnam-Linked Database
Security researchers discovered a misconfigured Elasticsearch database exposing 220 million passenger and crew records, including passport numbers and detailed flight data spanning 2017 to 2026. The Vietnam-linked APIS system was accessible for years before being secured in June. No dark web sales have surfaced yet, but the breach raises serious questions about border data protection.
220 million traveler records exposed in Vietnam-linked APIS leak
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]
220M Travel Records Exposed Through Default Credentials
Changing default credentials should be a no-brainer, yet researchers still found a route into a database holding more than 220 million passenger and crew records using default login details. Researchers from Kinryū Labs found 220,783,700 passenger and crew records in an APIS database hosted on Viettel-assigned IP space in Hanoi. The information covers more than nine years of sensitive records that could link a traveler to specific flights, dates…
Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details
A series of misconfigurations allowed researchers to access a treasure trove of sensitive data - the archive has since been locked down.
Exposed Database Left 220Mn Airline Passenger, Crew Records Open To The Internet
A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed. The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler ident…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












