Vietnam-linked APIS database exposes 220 million passenger and crew records
Security researchers disclosed that an unsecured Advance Passenger Information System database hosted in Vietnamese IP space had exposed roughly 220 million passenger and crew travel records spanning 2017 to 2026 through misconfigurations and default credentials.
- Victim
- Vietnam-linked APIS database
- records
- 220.8M
On 8 September 2026, security researchers at Kinryū Labs disclosed that an unsecured Advance Passenger Information System (APIS) database had exposed roughly 220 million passenger and crew travel records. The database, an Elasticsearch cluster named 'pax-info', had been discovered on 3 June 2026 sitting on the public internet, reachable through a chain of security misconfigurations and default credentials. It was hosted in Viettel-assigned IP space in Hanoi, giving the leak a Vietnamese connection, though researchers could not confirm which organisation operated the system.
APIS data is the traveller information airlines transmit to border authorities before a flight. The exposed cluster held roughly 107 GB of data across 29 indices, with its two principal indices containing about 210,318,069 passenger records and 10,465,631 crew records — a combined 220,783,700 entries spanning January 2017 to April 2026. Fields included names, dates of birth, sex, nationalities, passport and travel-document numbers with expiry dates and issuing countries, plus flight numbers and dates, airlines, airport codes, seat assignments and baggage references.
An unclaimed, high-sensitivity exposure
Because the data was left reachable through misconfiguration rather than stolen in an intrusion, no threat actor claimed the exposure, and it was not attributed to any attacker. The sensitivity of the combination — full identity and passport details tied to detailed movement histories — makes the trove especially valuable for fraud, surveillance and targeting, even absent evidence of malicious download.
As of the disclosure, the operator of the 'pax-info' cluster had not been identified and the exposure had not been publicly tied to a specific airline, ground handler or government agency, so remediation status could not be independently confirmed. The incident's status therefore remained unknown.
Timeline
Researchers at Kinryū Labs discover a publicly reachable Elasticsearch cluster named 'pax-info' hosted in Viettel-assigned IP space in Hanoi.
Kinryū Labs discloses the exposure to journalists; media report that 220 million passenger and crew records were reachable without proper authentication.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
- securityaffairs.comhttps://securityaffairs.com/198671/data-breach/massive-vietnam-linked-apis-database-exposes-passport-and-flight-data.html
- oodaloop.comhttps://oodaloop.com/briefs/cyber/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/