Over 220 Million Traveler Records Exposed in Vietnam-Linked APIS Database Leak

Passport numbers and flight details spanning nine years accessible online through chained security misconfigurations

edit
By LineZotpaper
Published
Read Time3 min
An Advance Passenger Information System (APIS) database containing more than 220 million passenger and crew records, including passport numbers and flight details, was left accessible online through a chain of security misconfigurations, security researchers Kinryū Labs have discovered. The exposed data, spanning January 2017 to April 2026, appears linked to a Vietnamese organization and could affect travelers of many nationalities who flew to, from, or through Vietnam during that period.

Security researchers at Kinryū Labs discovered the exposed Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster, named 'pax-info', contained 29 indices and approximately 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries.

According to Kinryū Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system.

The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times — information typically carried by APIS and related airline systems.

Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others. While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers' own travel to Vietnam. The figures represent travel records rather than unique individuals; passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

Kinryū Labs told BleepingComputer that it reached the database by chaining two misconfigurations. From the open internet, the endpoint returned an HTTP 401 "Unauthorized" response, preventing direct access. However, a cloud-based path enabled researchers to reach the cluster, which then accepted default credentials.

Internet intelligence platform FOFA first recorded the host and port in October 2022 and identified the service as a database in July 2023. However, Kinryū Labs could not determine when the passenger data first became retrievable through the second access path. As a result, while the records themselves span more than nine years, the actual length of the exposure is unknown.

§

Analysis

Why This Matters

  • 220 million travel records containing passport data and flight details could enable identity theft, phishing scams targeting travelers, or other forms of fraud.
  • The leak exposes systemic vulnerabilities in border security infrastructure — the very systems designed to protect travelers are themselves unsecured.
  • The actual exposure window is unknown, meaning the data may have been accessible to malicious actors for months or years before discovery.

Background

Advance Passenger Information Systems (APIS) are used by governments worldwide to collect identity and flight data from airlines before travelers arrive or depart. They form a critical component of border security and immigration processing. This is not the first large-scale travel data exposure — similar leaks have occurred in other countries, but the scale here (220 million records over nine years) makes it one of the largest known APIS-related breaches. The data appears linked to a Vietnamese organization, but the operator has not been publicly identified.

Key Perspectives

Affected Travelers: Their personal data, including passport numbers and travel itineraries, has been exposed. They face risks of identity theft, fraudulent visa applications, or targeted phishing attacks using legitimate-looking travel data. The Responsible Organization (unidentified): Likely faces significant reputational damage and potential regulatory action under data protection laws. The use of default credentials indicates weak security practices. Security Researchers (Kinryū Labs): Have responsibly disclosed the vulnerability, but the affected organization has not been confirmed, leaving the data potentially still exposed.

What to Watch

  • Whether the Vietnamese organization or government publicly acknowledges the leak and notifies affected travelers.
  • Regulatory action by Vietnam's data protection authority or international bodies under laws like GDPR (if EU citizens are among the exposed).
  • Any reports of the data being used in phishing campaigns or appearing on criminal forums.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.