Skip to content
Tech News
← Back to articles

220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak

read original get Zoppen RFID-Blocking Passport Holder Wallet → more articles
Why This Matters

A misconfigured Elasticsearch cluster tied to Vietnam's Advance Passenger Information System left more than 220 million passenger and crew travel records open, including passport numbers, dates of birth, and detailed itineraries spanning 2017 to 2026. Because APIS data is collected from airlines worldwide, the exposure touches travelers of many nationalities who transited Vietnam, making it a prime resource for identity fraud and state-level tracking. It also shows how government border-security systems, not just airlines, can become the weakest link in aviation data security.

Key Takeaways
Worth a Look

Zoppen RFID-Blocking Passport Holder Wallet — Stories like this leak are a reminder that your passport details are valuable data worth guarding wherever you can. A Zoppen RFID-blocking passport wallet keeps your passport, boarding passes and cards organized in one place while shielding chip-enabled documents from casual wireless skimming at crowded airports.

See Zoppen RFID-Blocking Passport Holder Wallet on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A misconfigured Advance Passenger Information System (APIS) database linked to Vietnam exposed more than 220 million passenger and crew travel records spanning 2017 to 2026, including names, passport numbers, nationalities, flight details, seat assignments, and baggage references. Researchers said the database was reachable through a chain of security mistakes and default credentials. It was later secured after the disclosure, but it's unclear whether the data had already been copied or abused. BleepingComputer reports: Kinryu Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries. According to Kinryu Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems. Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others. While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period. Kinryu Labs expects to publish additional details on its blog later this week.

Read more of this story at Slashdot.