220 million traveler records exposed in Vietnam-linked APIS leak

More than 220 million passenger and crew records have been left exposed online through a series of security misconfigurations linked to a Vietnamese organization. The Advance Passenger Information System (APIS) database, which holds sensitive information on travelers from around the world, was accessible to anyone with the right credentials. The leak is a sobering reminder that even seemingly secure systems can be vulnerable to exploitation.

The exposed records, which span nine years and include passport numbers, flight details, and passenger names, could involve travelers of many nationalities who flew through Vietnam during this period. Kinryū Labs, the researchers who discovered the issue, believe the system was operated by a Vietnamese organization, although the exact identity of the responsible party remains unclear.

APIS databases are used worldwide to collect sensitive information from airlines before passengers and crew arrive at or depart from a country. This data is typically stored securely, but in this case, it appears that a combination of misconfigurations allowed researchers to access the database through an Elasticsearch cluster named ‘pax-info’. The cluster contained over 107 GB of data, including passenger records and crew information.

The exposed data included names, dates of birth, nationalities, passport numbers, and associated travel details such as flight numbers, airlines, and departure and destination airports. While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against their own travel to Vietnam. However, it’s worth noting that the figures represent travel records rather than unique individuals – passengers and crew members who flew multiple times may appear repeatedly in the database.

The researchers were able to access the database through a chain of misconfigurations, which allowed them to bypass initial security measures. The cloud-based path enabled default credentials to be accepted by the cluster, allowing Kinryū Labs to access the sensitive information. While it’s unclear how long the exposure lasted or whether the data was downloaded or sold, researchers reported the issue to Vietnamese authorities and airlines represented in the database as soon as they discovered it.

In response to the leak, several major airlines have been informed, although there is no indication that their own networks were compromised. Singapore Airlines’ security team helped coordinate the response, informing Kinryū Labs on June 8 that steps had been taken to contain the issue. However, Vietnamese authorities and some airlines declined to comment when approached by BleepingComputer.

This incident serves as a stark reminder of the importance of robust cybersecurity measures, even for seemingly secure systems. As researchers continue to probe exposed databases and networks, it’s essential for individuals and organizations to remain vigilant and proactive in protecting sensitive information.


Source: Bleeping Computer — 2026-09-08