Skip to content
Tech News
← Back to articles

220 million traveler records exposed in Vietnam-linked APIS leak

read original get Zoppen RFID-Blocking Passport Holder Wallet → more articles
Why This Matters

A misconfigured Elasticsearch cluster exposed more than 220 million passenger and crew records tied to Vietnam's Advance Passenger Information System, including passport numbers, birth dates, nationalities and detailed flight itineraries spanning 2017 to 2026. Because APIS data is government-mandated border information, the leak affects travelers of many nationalities who flew to, from, or through Vietnam, creating identity fraud and surveillance risks well beyond a typical airline breach.

Key Takeaways
Worth a Look

Zoppen RFID-Blocking Passport Holder Wallet — With passport numbers and flight details in the news, it's a good moment to tighten up your own travel document habits. This Zoppen passport wallet keeps your passport, boarding passes, and cards organized in one place with RFID-blocking material to shield chipped documents while you move through airports.

See Zoppen RFID-Blocking Passport Holder Wallet on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it.

Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country.

The exposed records span January 2017 to April 2026 and could involve travelers of many nationalities who flew to, from, or through Vietnam during that period.

Nine years of passenger and crew data

Kinryū Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity.

The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries.

According to Kinryū Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system.

The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries.

Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems.

Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others.

... continue reading