News: 0185624438

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak

(Sunday September 13, 2026 @10:34PM (BeauHD) from the another-day-another-leak dept.)


A misconfigured Advance Passenger Information System (APIS) database linked to Vietnam [1]exposed more than 220 million passenger and crew travel records spanning 2017 to 2026 , including names, passport numbers, nationalities, flight details, seat assignments, and baggage references. Researchers said the database was reachable through a chain of security mistakes and default credentials. It was later secured after the disclosure, but it's unclear whether the data had already been copied or abused. BleepingComputer reports:

> Kinryu Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries. According to Kinryu Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system.

>

> The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems.

>

> Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others. While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryu Labs expects to publish additional details on [2]its blog later this week.



[1] https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/

[2] https://kinryu.sh/reports/vietnam-apis-exposure/



So what (Score:2)

by tiananmen tank man ( 979067 )

So someone knows x on date y was assigned a window seat on flight n, big deal.

Re: (Score:3)

by cawdor ( 10162661 )

Names, date of birth and passport numbers are the big ticket items here. You can combine this with other data and get a ton of personal info that can be used for all kinds of crime. So yes it is a big deal.

Re: (Score:2)

by 93 Escort Wagon ( 326346 )

Not to mention that, in a month or two, we'll probably learn that credit card info from the ticket purchase was somehow "mistakenly" tied to this database and was also exposed. And, in addition...

> ... but it's unclear whether the data had already been copied or abused.

Don't worry, I'm sure these researchers were the first to discover this. :rolleyes:

Coward, n.:
One who in a perilous emergency thinks with his legs.
-- Ambrose Bierce, "The Devil's Dictionary"